Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security team is implementing a new access control system. The policy dictates that users should only have the minimum necessary access rights to perform their job functions, and these rights should be revoked automatically when their role changes or they leave the company. Which security principle is being enforced by this policy?
- ASeparation of Duties
- BDefense in Depth
- CLeast Privilege
- DImplicit Deny
Show answer & explanationAnswer & explanation
Correct answer: C. Least Privilege
The principle of least privilege dictates that users, programs, or processes should be granted only the minimum access necessary to perform their legitimate functions. Revoking access when roles change or employment ends further reinforces this principle by ensuring privileges are always kept to the absolute minimum required.
Why the other options are wrong
- A. Separation of duties prevents one individual from completing a critical task alone, not about the amount of access.
- B. Defense in depth uses multiple layers of security, a broader strategy not specifically addressed by this access policy.
- D. Implicit deny is a firewall rule that blocks all traffic not explicitly allowed, a technical control, not a user access principle.
Principle of Least Privilege
A security principle requiring that a user or process be given only the minimum necessary authorization to perform its function.
- Reduces the attack surface.
- Limits the damage from compromised accounts.
- Requires regular review of access rights.
Memory trick: Least Privilege: Only give them the keys they need, no extra.