Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

A security team is implementing a new access control system. The policy dictates that users should only be granted the minimum necessary permissions to perform their job functions and no more. For example, a data entry clerk should only have read/write access to specific database tables and no administrative privileges. Which security principle is being applied?

  1. ASeparation of Duties
  2. BNeed to Know
  3. CDefense in Depth
  4. DPrinciple of Least Privilege
Show answer & explanation

Correct answer: D. Principle of Least Privilege

The Principle of Least Privilege states that users, programs, or processes should be given only the minimum level of access or permissions necessary to perform their legitimate functions and no more. This limits the potential damage if an account or system is compromised.

Why the other options are wrong

  • A. Separation of duties distributes critical tasks among different individuals to prevent a single point of failure or fraud, which is different from granting minimum permissions to one user.
  • B. Need to Know is a concept where access to information is granted only if it is essential for an individual's job function, which is a specific application of the broader Principle of Least Privilege.
  • C. Defense in depth involves multiple layers of security controls, not a specific access rights principle.

Principle of Least Privilege

A security principle requiring that a user, program, or process be given only the minimum necessary authorization to perform its function. This limits the potential damage that can be caused by an attacker or a compromised system.

  • Reduces the attack surface and potential impact of breaches.
  • Should be applied to users, applications, and services.
  • Requires careful access review and management.

Memory trick: Least Privilege: Give them just enough 'keys' to do their job, and no more.

More Security Concepts questions