PrepAway - Latest Free Exam Questions & Answers

which of the following?

The end result of implementing the principle of least privilege means which of the following?

PrepAway - Latest Free Exam Questions & Answers

A.
Users would get access to only the info for which they have a need to know

B.
Users can access all systems.

C.
Users get new privileges added when they change positions.

D.
Authorization creep.

Explanation:
Least privilege means an individual should have just enough permissions and rights to fulfill his role in the
company and no more.
Incorrect Answers:
B Least privilege means an individual should have just enough permissions and rights to fulfill his role in the
company and no more. Not all users in an organization requires access to all systems.
C: The principle of least privilege would require that the rights required for the position be closely evaluated and
where possible rights revoked.
D: Authorization creep occurs when users are given additional rights with new positions and responsibilities.
The principle of least privilege should actually prevent authorization creep.

Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 281, 1236
https://en.wikipedia.org/wiki/Principle_of_least_privilege


Leave a Reply