Rebecca, a security professional, was instructed to limit employees’ access to critical resources. For this purpose, she implemented an access principle that provides permission to access only necessary resources that are required for their job tasks. The permissions can be extended later based on changes in their job roles. Identify the access principle implemented by Rebecca in the above scenario.Group of answer choicesPrinciple of least privilege (POLP)Rule-based access controlNeed-to-knowSeparation of duties (SoD)
Question
Rebecca, a security professional, was instructed to limit employees’ access to critical resources. For this purpose, she implemented an access principle that provides permission to access only necessary resources that are required for their job tasks. The permissions can be extended later based on changes in their job roles. Identify the access principle implemented by Rebecca in the above scenario.Group of answer choicesPrinciple of least privilege (POLP)Rule-based access controlNeed-to-knowSeparation of duties (SoD)
Solution
The access principle implemented by Rebecca in the scenario is the Principle of Least Privilege (POLP). This principle states that a user should have the least amount of privileges necessary to perform their job functions. This can help to reduce the potential damage caused by errors or malicious activity.
Similar Questions
Question 81 ptsWhat type of access control approaches is suitable when several people in the organization perform the same role or task? Group of answer choicesLattice-based access controlDiscretionary access controlMandatory access controlRole/task-based access control
Which of the following security design principles says ‘access decisions should be based on permission rather than exclusion’?Group of answer choicesFail-safe defaultsComplete mediationSeparation of privilegeLeast Astonishment
Permits the specification and enforcement of enterprise-specific security policies in a way that maps more naturally to an organization's structure and business activities.System Access controlRole-based access controlDiscretionary access controlMandatory access control;
How can the principle of least privileged access be implemented in AWS?a)By granting all users full access to all resourcesb)By granting users permissions based on their job titlesc)By granting users permissions based on their seniority in the organizationd)By granting users the minimum permissions necessary to perform their tasks
An organization plans to implement security training to educate employees about security policies. What type of access control is the organization trying to implement?Question 30Select one:logicaltechnologicaladministrativephysical
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.