Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A cybersecurity analyst is investigating an incident where unauthorized access to a cloud-based database occurred. The investigation reveals that the database was configured with overly permissive access policies, allowing external users to read and write data without proper authentication. Which security principle was most likely violated?

  1. AData Redundancy
  2. BHigh Availability
  3. CElasticity
  4. DLeast Privilege
Show answer & explanation

Correct answer: D. Least Privilege

The principle of Least Privilege dictates that users and systems should only be granted the minimum necessary permissions to perform their tasks. Overly permissive access policies directly violate this principle, leading to potential unauthorized access.

Why the other options are wrong

  • A. Data Redundancy refers to having duplicate copies of data for disaster recovery, not access control.
  • B. High Availability relates to system uptime and accessibility, not access control permissions.
  • C. Elasticity is the ability to scale resources up or down, unrelated to access policies.

Least Privilege

A security principle requiring that a user or system be given only the minimum levels of access or permissions needed to perform its job function.

  • Reduces the attack surface
  • Limits damage from compromised accounts
  • Essential for strong access control

Memory trick: Don't Give Too Much, Just Enough Privilege.

More Cloud Security questions