Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A company is implementing a new security measure to ensure that employees can only access corporate resources from devices that meet specific security standards, such as having up-to-date antivirus software and an encrypted hard drive. Which security concept is this measure primarily designed to enforce?

  1. ALeast Privilege
  2. BSeparation of Duties
  3. CAccess Control
  4. DDefense in Depth
Show answer & explanation

Correct answer: C. Access Control

This measure dictates who (employees) can access what (corporate resources) under specific conditions (device security standards). This directly falls under the umbrella of access control, which manages and restricts access to resources.

Why the other options are wrong

  • A. Least Privilege grants users only the minimum access necessary for their job, which is related but not the primary concept described here.
  • B. Separation of Duties prevents a single person from controlling an entire critical process, which is unrelated to device security standards.
  • D. Defense in Depth involves multiple layers of security, which is a broader strategy, not the specific mechanism described.

Access Control

A security technique that regulates who or what can view or use resources in a computing environment. It enforces policies that determine authorized access.

  • Involves authentication (who you are) and authorization (what you can do).
  • Can be physical (doors) or logical (passwords, firewalls).
  • Often implemented through Access Control Lists (ACLs) or Role-Based Access Control (RBAC).

Memory trick: Access Control is like a bouncer checking your ID and permissions.

More Security Principles questions