Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

An organization is implementing a new security policy that dictates all users must have the minimum necessary permissions to perform their job functions and nothing more. This policy is designed to limit the potential damage from compromised accounts or insider threats. Which security principle is this organization enforcing?

  1. ALeast Privilege
  2. BSeparation of Duties
  3. CNon-repudiation
  4. DDefense in Depth
Show answer & explanation

Correct answer: A. Least Privilege

The principle of Least Privilege states that users should be granted only the minimum necessary permissions to perform their job functions. This directly aligns with the organization's policy to limit potential damage.

Why the other options are wrong

  • B. Separation of Duties divides critical tasks among multiple individuals to prevent fraud or error.
  • C. Non-repudiation ensures that a party cannot deny having performed an action.
  • D. Defense in Depth involves using multiple layers of security controls.

Least Privilege

A security principle where a user or process is granted only the minimum access rights needed to perform its function.

  • Reduces the attack surface.
  • Limits potential damage from breaches.
  • Fundamental to secure system design.

Memory trick: Least Privilege: 'Just enough keys, not the whole keyring.'

More Describe the concepts of security, compliance, and identity questions