Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy
A security architect is designing a secure network architecture for a cloud-native application. The application consists of several microservices, and each microservice needs to communicate securely with specific other microservices and a backend database. Overly broad network access rules are a concern. Which security principle should be applied to restrict communication between these components to only what is absolutely necessary?
- ALeast Privilege
- BShared Responsibility
- CSecurity by Obscurity
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: A. Least Privilege
The principle of Least Privilege dictates that each component or user should only have the minimum necessary permissions to perform its function. Applying this to network communication means restricting access to only the necessary ports and protocols between microservices.
Why the other options are wrong
- B. Shared Responsibility defines who is responsible for what in the cloud, not a principle for restricting internal component communication.
- C. Security by Obscurity relies on hiding information, which is not a robust security principle and does not restrict network access.
- D. Defense in Depth involves multiple layers of security controls, but doesn't specifically address restricting communication to only what is necessary at a granular level.
Principle of Least Privilege
A security principle requiring that a user, program, or process be granted only the minimum access rights necessary to perform its task.
- Reduces the attack surface.
- Limits the damage from successful attacks.
- Applies to user permissions, network access, and application roles.
Memory trick: Least Privilege: Only the keys you need, nothing more.