Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A security auditor is reviewing an organization's access control policies. They find that several employees have been granted administrative privileges to systems even though their job roles do not require such elevated access. This directly violates which fundamental security concept?

  1. ADefense in Depth
  2. BLeast Privilege
  3. CSeparation of Duties
  4. DNeed to Know
Show answer & explanation

Correct answer: B. Least Privilege

The principle of least privilege dictates that users should only be granted the minimum level of access necessary to perform their job functions. Granting administrative privileges beyond what is required for a role is a direct violation of this principle.

Why the other options are wrong

  • A. Defense in Depth involves multiple layers of security controls.
  • C. Separation of Duties divides critical tasks among multiple individuals to prevent fraud.
  • D. Need to Know is an access control principle where access is granted only when required for specific tasks.

Principle of Least Privilege (PoLP)

A security principle requiring that a user or process be granted only the minimum access rights necessary to perform its job function or task.

  • Reduces the attack surface and potential damage from compromise.
  • Applies to users, applications, and systems.
  • Often implemented through granular access controls and role-based access control (RBAC).

Memory trick: Access: Least privilege, need to know, separation of duties, defense in depth.

More Security Principles questions