Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
An organization is conducting a security audit. The auditor discovers that several employees have elevated access privileges that are no longer required for their current job roles. This finding indicates a failure in adhering to which fundamental security principle?
- ASecurity by Obscurity
- BSeparation of Duties
- CLeast Privilege
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: C. Least Privilege
The principle of Least Privilege dictates that users should only be granted the minimum access necessary to perform their job functions. Having unnecessary elevated privileges directly violates this principle.
Why the other options are wrong
- A. Security by Obscurity relies on hiding information, which is not a recognized security principle and doesn't apply here.
- B. Separation of duties prevents one person from controlling an entire critical process, which is different from individual privilege levels.
- D. Defense in Depth involves multiple layers of security, not specifically individual user permissions.
Principle of Least Privilege
A security concept that requires that a user be given only the minimum levels of access or permissions needed to perform their job function.
- Reduces the attack surface and potential damage from compromise.
- Applies to users, processes, and applications.
- Requires regular review and adjustment of permissions.
Memory trick: Access control is about who gets in and how much they can do.