ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium

A network administrator is configuring network access for a new department. Users in this department need to access specific internal web applications and a database server. To minimize the attack surface, the administrator wants to ensure that only necessary ports are open from the department's subnet to the application and database servers. Which network security principle is the administrator applying by restricting ports to only those required?

  1. ASeparation of duties
  2. BDefense in depth
  3. CLeast privilege
  4. DFail-safe defaults
Show answer & explanation

Correct answer: C. Least privilege

The principle of least privilege dictates that users and systems should only be granted the minimum necessary access rights or permissions required to perform their legitimate functions. In this context, opening only necessary ports is an application of least privilege at the network level.

Why the other options are wrong

  • A. Separation of duties divides critical tasks among multiple individuals to prevent fraud or error, unrelated to port configuration.
  • B. Defense in depth involves multiple layers of security controls, which is a broader strategy, not specific to port restriction.
  • D. Fail-safe defaults ensure that if a system fails, it defaults to a secure state, which is not directly related to port restriction in normal operation.

Least Privilege (Network)

A security principle applied to networks that dictates granting only the minimum necessary access rights (e.g., open ports, allowed protocols) required for a system or user to perform its function.

  • Reduces attack surface by limiting exposure.
  • Minimizes potential damage from compromise.
  • Applies to users, processes, and network resources.

Memory trick: Least Privilege: Just enough, no more.

More Communication and Network Security questions