Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard

A company recently underwent a major organizational restructuring, resulting in many employees changing departments or roles. The existing security policies include guidelines for data access based on job function, but the process for reviewing and updating these access rights has not been consistently followed during the transition. This oversight directly increases the risk of violating which security principle?

  1. ADefense in Depth
  2. BConfidentiality, Integrity, and Availability (CIA) Triad
  3. CSeparation of Duties
  4. DLeast Privilege
Show answer & explanation

Correct answer: D. Least Privilege

If employees retain access rights from previous roles that are no longer necessary for their current job functions, it directly violates the principle of Least Privilege, which dictates that users should only have the minimum access required.

Why the other options are wrong

  • A. Defense in Depth involves multiple layers of security controls, not specifically individual access rights management.
  • B. While violating Least Privilege can impact CIA, Least Privilege is the more direct principle being violated in this scenario of excessive permissions.
  • C. Separation of Duties prevents a single individual from performing critical, conflicting tasks, which is distinct from simply having too much access for one's role.

Least Privilege Principle

The practice of granting users only the minimum necessary access rights to perform their job functions, thereby reducing the attack surface and potential damage from a compromise.

  • Crucial for access control and authorization.
  • Requires regular review and adjustment of permissions.
  • Helps prevent insider threats and lateral movement by attackers.

Memory trick: Oversight in access means keys are given out too freely.

More Security Policies and Procedures questions