Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignMedium

A security architect is reviewing a cloud application design that uses multiple microservices, each deployed as a separate container. To enhance security, they want to ensure that each microservice has the minimum necessary privileges to perform its function and that communication between microservices is strictly controlled based on defined policies. Which security principle is being applied here?

  1. ALeast Privilege
  2. BAbstraction
  3. CDefense in Depth
  4. DSeparation of Duties
Show answer & explanation

Correct answer: A. Least Privilege

The principle of Least Privilege dictates that each entity (in this case, a microservice) should be granted only the minimum necessary permissions to perform its function, and no more. This directly addresses ensuring minimum necessary privileges and strictly controlled communication.

Why the other options are wrong

  • B. Abstraction is about hiding complexity, not a security principle for access control.
  • C. Defense in Depth involves multiple layers of security controls, but 'minimum necessary privileges' is a more specific principle.
  • D. Separation of Duties prevents a single individual from completing a critical task end-to-end, not directly about microservice permissions.

Least Privilege

A security principle that requires that an individual or process be granted only the minimum necessary access rights or permissions to perform its job function, and no more.

  • Reduces the attack surface.
  • Limits the impact of a compromise.
  • Applies to users, processes, services, and applications.

Memory trick: CIA Triad and beyond: Confidentiality, Integrity, Availability, plus these key design rules.

More Cloud Concepts, Architecture and Design questions