Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy
A company is implementing a security policy that states: 'Users should only have access to the resources absolutely necessary to perform their job functions, and for the shortest possible duration.' Which security principle is being directly applied here?
- ADefense in Depth
- BSeparation of Duties
- CShared Responsibility
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: D. Least Privilege
The principle of Least Privilege dictates that users and processes should be granted only the minimum necessary permissions to perform their tasks, and for the minimum duration required.
Why the other options are wrong
- A. Defense in Depth involves multiple layers of security controls, not specifically access rights.
- B. Separation of Duties prevents one person from completing a critical task alone, focusing on preventing fraud/error.
- C. Shared Responsibility clarifies security duties between cloud provider and customer, not internal user access.
Least Privilege
A security principle where every user, program, and process is granted only the minimum necessary permissions to perform its intended function, and for the shortest possible duration.
- Reduces the attack surface.
- Limits potential damage from breaches or errors.
- Essential for strong security posture.
Memory trick: Least Privilege: Give them just enough key to open their own door, not the whole building.