Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsEasy
A financial services company is implementing a new compliance framework that requires strict control over who can access sensitive customer data and what actions they can perform. This includes ensuring that employees only have the minimum necessary access rights to fulfill their job duties. Which cybersecurity concept is this company primarily demonstrating?
- AAttack Surface Reduction
- BZero-Day Exploitation
- CPrinciple of Least Privilege
- DSecurity through Obscurity
Show answer & explanationAnswer & explanation
Correct answer: C. Principle of Least Privilege
The scenario directly describes the Principle of Least Privilege, which dictates that users and systems should only be granted the minimum necessary permissions to perform their required tasks.
Why the other options are wrong
- A. Attack Surface Reduction aims to minimize points of entry for attackers, which is a broader concept not specifically focused on user permissions.
- B. Zero-Day Exploitation refers to attacks using unknown vulnerabilities, unrelated to access control policies.
- D. Security through Obscurity relies on hiding information, which is not a recommended security practice.
Principle of Least Privilege (PoLP)
A security concept in which a user, program, or process is given only the minimum necessary rights, permissions, or access level to perform its function.
- Minimizes potential damage from compromised accounts.
- Reduces the attack surface.
- A fundamental security best practice.
Memory trick: Only give the key to exactly what they need, not the whole house.