Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy

A security auditor is reviewing the access controls for a Kubernetes cluster. They notice that several service accounts and user roles have been granted broad permissions, such as `cluster-admin` or `edit` on all namespaces, even for applications that only require access to specific resources in a single namespace. This configuration significantly increases the potential blast radius in case of a compromise. Which fundamental security principle is being violated in this scenario?

  1. APrinciple of Least Privilege
  2. BSecurity by Obscurity
  3. CDefense in Depth
  4. DZero Trust Architecture
Show answer & explanation

Correct answer: A. Principle of Least Privilege

The Principle of Least Privilege dictates that users, service accounts, and processes should only be granted the minimum necessary permissions to perform their intended functions. Granting broad, unnecessary permissions directly violates this principle.

Why the other options are wrong

  • B. Security by Obscurity relies on hiding information, which is unrelated to granting broad permissions.
  • C. Defense in Depth involves multiple layers of security controls, which might still be present even with overly permissive access.
  • D. Zero Trust Architecture assumes no implicit trust, but overly permissive roles still violate the core tenet of verifying and limiting access.

Principle of Least Privilege (PoLP)

A security principle that requires every user, program, and process to be granted only the minimum set of permissions necessary to perform its function, and no more.

  • Minimizes potential damage from compromises.
  • Reduces the attack surface.
  • A cornerstone of secure system design.

Memory trick: Least privilege means only the keys you need.

More Cloud Native Security questions