Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A company is conducting a security assessment of its external-facing web applications. They discover that one application uses a default administrative password and has several unnecessary services running on its web server. Which of the following best describes the security principle being violated?

  1. APrinciple of Defense in Depth
  2. BPrinciple of Least Privilege
  3. CPrinciple of Separation of Duties
  4. DPrinciple of Least Functionality
Show answer & explanation

Correct answer: D. Principle of Least Functionality

The presence of unnecessary services and default administrative passwords indicates that the system has more functionality or configuration than required for its intended purpose, violating the principle of least functionality. This principle advocates for systems to run only the absolutely necessary services, applications, and configurations.

Why the other options are wrong

  • A. Defense in Depth is about layering security controls, not directly about reducing functionality.
  • B. Least Privilege relates to granting users/processes only the minimum access needed, not system functionality.
  • C. Separation of Duties involves dividing critical tasks among multiple individuals to prevent fraud/error, not system configuration.

Principle of Least Functionality

A security principle that dictates that systems and applications should be configured to provide only the essential capabilities required for their intended purpose, disabling or removing all unnecessary services, applications, and functions.

  • Reduces the attack surface.
  • Minimizes potential vulnerabilities.
  • Applies to operating systems, applications, and network devices.
  • Often involves removing default configurations and unnecessary software.

Memory trick: Security principles are rules for strong defenses; least functionality means only what's needed.

More Security Concepts questions