Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A small business is setting up its first cloud environment. They want to implement a security principle that minimizes the permissions granted to users and processes, ensuring they only have access to resources absolutely necessary to perform their function. Which security concept are they trying to implement?

  1. ADefense in Depth
  2. BSecurity by Obscurity
  3. CShared Responsibility Model
  4. DLeast Privilege
Show answer & explanation

Correct answer: D. Least Privilege

The concept of granting only the essential permissions required for a task is known as Least Privilege. This minimizes the potential damage from compromised accounts or errors.

Why the other options are wrong

  • A. Defense in Depth involves multiple layers of security controls, not specifically focused on individual user/process permissions.
  • B. Security by Obscurity relies on hiding information rather than implementing robust security controls, which is not a recommended practice.
  • C. The Shared Responsibility Model defines security duties between cloud providers and customers, not specific access permissions.

Least Privilege

A security principle where users and processes are granted only the minimum necessary permissions to perform their job functions.

  • Reduces the attack surface.
  • Limits potential damage from security breaches.
  • Applies to users, applications, and systems.

Memory trick: Grant only the key that unlocks the single necessary door.

More Describe the concepts of security, compliance, and identity questions