Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy
A global software development company is designing a Zero Trust strategy for its developer environment. Developers require access to various source code repositories, build servers, and testing environments. To minimize the attack surface and prevent unauthorized access, the security architects must ensure that each developer only has the absolute minimum permissions required to perform their current task, and these permissions should be revoked automatically when no longer needed. Which Zero Trust principle is being emphasized here?
- AEnd-to-End Encryption
- BVerify Explicitly
- CUse Least Privilege Access
- DAssume Breach
Show answer & explanationAnswer & explanation
Correct answer: C. Use Least Privilege Access
Use Least Privilege Access is a core Zero Trust principle that dictates users and systems should only be granted the minimum necessary permissions to perform their tasks. This includes just-in-time and just-enough access, which aligns perfectly with granting permissions only when needed and revoking them automatically.
Why the other options are wrong
- A. End-to-End Encryption is a data protection mechanism, not an access permission principle.
- B. Verify Explicitly is about authenticating and authorizing all access requests comprehensively.
- D. Assume Breach is about designing for and minimizing the impact of security incidents.
Use Least Privilege Access (Zero Trust)
A core Zero Trust principle that mandates granting users and systems only the minimum necessary permissions to perform their tasks, for the shortest possible duration.
- Minimizes the attack surface.
- Limits the impact of a compromised account.
- Often implemented with Just-In-Time (JIT) and Just-Enough-Access (JEA).
- Applies to users, applications, and devices.
Memory trick: Trust No One, Verify Everyone, Grant Least.