Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium
A company is implementing a new policy to restrict network access based on the roles and responsibilities of its employees. For example, the finance department should only be able to access financial servers, and HR should only access HR-related resources, even if they are on the same physical network segment. Which security principle is this policy primarily enforcing?
- ASeparation of duties
- BLeast privilege
- CDefense in depth
- DConfidentiality
Show answer & explanationAnswer & explanation
Correct answer: B. Least privilege
The principle of least privilege dictates that users should only be granted the minimum necessary permissions to perform their job functions. Restricting access based on roles to only the resources they need directly implements this principle.
Why the other options are wrong
- A. Separation of duties requires multiple individuals to complete a critical task, preventing a single point of failure or malicious act.
- C. Defense in depth involves multiple layers of security controls, which is a broader strategy.
- D. Confidentiality protects information from unauthorized disclosure, which is an outcome, not the primary principle of access restriction.
Least Privilege
The security principle that states users or processes should be granted only the minimum necessary access rights to perform their job or function.
- Minimizes potential damage from errors or malicious acts.
- Reduces the attack surface.
- Applies to users, applications, and systems.
Memory trick: Security principles are the foundational rules for keeping things safe.