nerdexam
(ISC)2(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #636

CERTIFIED-IN-CYBERSECURITY Question #636: Real Exam Question with Answer & Explanation

The correct answer is A: The principle that users should only be given the minimum level of access necessary to perform. The principle of least privilege is the principle that users should only be given the minimum level of access necessary to perform their job functions, in order to reduce the risk of unauthorized access and limit the potential damage that could be caused by a compromised account.

Access Controls Concepts

Question

What is the principle of least privilege?

Options

  • AThe principle that users should only be given the minimum level of access necessary to perform
  • BThe principle that all users should have equal access to all resources on a network.
  • CThe principle that security controls should be implemented based on the perceived risk level of
  • DThe principle that users should be given access to all resources by default, unless otherwise

Explanation

The principle of least privilege is the principle that users should only be given the minimum level of access necessary to perform their job functions, in order to reduce the risk of unauthorized access and limit the potential damage that could be caused by a compromised account.

Topics

#Least Privilege#Access Control#Security Principles

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY PracticeBrowse All CERTIFIED-IN-CYBERSECURITY Questions