Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy
A security analyst is investigating a network segment where several critical servers are hosted. The analyst observes a high volume of traffic originating from these servers towards external, unknown IP addresses on various non-standard ports, even during periods of low legitimate activity. There is no business justification for these servers to initiate outbound connections to arbitrary external destinations. Which security principle is most directly being violated in this scenario?
- ASeparation of Duties
- BLeast Privilege
- CConfidentiality
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: B. Least Privilege
The observed behavior indicates that the critical servers have more network access than required for their intended function, allowing them to initiate unauthorized outbound connections. This directly violates the principle of least privilege, which dictates that entities should only have the minimum necessary permissions to perform their tasks.
Why the other options are wrong
- A. Separation of Duties prevents a single individual from controlling multiple critical aspects of a process, which is not directly related to server network access.
- C. Confidentiality protects data from unauthorized disclosure, but the primary violation here is excessive access, not necessarily data disclosure itself, although it could be a consequence.
- D. Defense in Depth involves multiple layers of security, which might exist but isn't the specific principle violated by excessive server permissions.
Least Privilege
A security principle that requires users, programs, or processes to be granted only the minimum necessary permissions to perform their work.
- Minimizes attack surface
- Reduces impact of security breaches
- Applies to network access, file permissions, user roles
Memory trick: Always grant ONLY what's needed.