Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
A security analyst is reviewing the organization's current access control policies. They notice that several employees, who have recently transferred departments, still retain elevated permissions from their previous roles, despite no longer requiring them. This scenario represents a direct violation of which security principle?
- ALeast Privilege
- BNeed-to-Know
- CSeparation of Duties
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: A. Least Privilege
The scenario describes employees having more permissions than necessary for their current job functions. This directly contradicts the principle of least privilege, which dictates that users should only have the minimum access required to perform their tasks. Failing to revoke unnecessary permissions increases the attack surface.
Why the other options are wrong
- B. Need-to-Know dictates that access to information should be granted only when specifically required to perform a task.
- C. Separation of Duties focuses on dividing critical tasks among multiple individuals to prevent fraud or error.
- D. Defense in Depth involves using multiple layers of security controls to protect assets.
Principle of Least Privilege
A security principle where users are granted only the minimum access rights and resources necessary to perform their assigned job functions, and no more.
- Minimizes potential damage from errors or malicious activity.
- Reduces the attack surface.
- Requires regular review and adjustment of access rights.
Memory trick: LEAST access for the LEAST risk.