A global technology company is developing an internal policy for cloud service adoption. The policy mandates that all cloud services must comply with the 'principle of least privilege' for data access. Which of the following best describes the primary rationale for applying this principle to cloud data?
- ATo minimize the cost of cloud storage by reducing data replication.
- BTo simplify data migration processes between different cloud providers.
- CTo reduce the attack surface and limit potential damage from unauthorized access or breaches.
- DTo accelerate application development cycles by streamlining access requests.
Show answer & explanationAnswer & explanation
Correct answer: C. To reduce the attack surface and limit potential damage from unauthorized access or breaches.
The principle of least privilege dictates that users and systems should only have the minimum necessary access rights to perform their functions. Applying this to cloud data primarily reduces the attack surface and limits the potential damage or scope of a breach by restricting what an attacker or compromised entity can access.
Why the other options are wrong
- A. Least privilege is an access control principle, not directly related to storage costs or replication.
- B. This principle does not simplify data migration; it focuses on access control.
- D. While it can streamline *proper* access, its primary purpose is security, not development acceleration.
Principle of Least Privilege
The Principle of Least Privilege (PoLP) is a security concept that ensures users, programs, or processes are granted only the minimum necessary rights or permissions to perform their authorized functions, thereby limiting the potential damage from errors or malicious actions.
- Grants minimum necessary access.
- Reduces attack surface.
- Limits impact of security breaches or errors.
Memory trick: Minimum keys mean minimum damage if they're lost.