Which statement best describes least privilege in information security?

Prepare for the MED Senior Leader Course SAE 2 Test. Study with detailed explanations, flashcards, and multiple-choice questions. Be confident on exam day!

Multiple Choice

Which statement best describes least privilege in information security?

Explanation:
Least privilege means giving users only the minimum permissions they need to perform their job. This limits access to sensitive data and critical systems, so even if an account is compromised or misused, the potential damage is contained. It’s implemented with controls like role-based access, need-to-know access, and regular reviews to adjust permissions as roles change. The described approach in the best statement directly embodies this idea by restricting access to what’s necessary. The other statements miss the point: granting broad access for convenience undermines security, eliminating encryption is not related to privileges and weakens protection, and replacing audits with something else ignores ongoing accountability and monitoring essential to security.

Least privilege means giving users only the minimum permissions they need to perform their job. This limits access to sensitive data and critical systems, so even if an account is compromised or misused, the potential damage is contained. It’s implemented with controls like role-based access, need-to-know access, and regular reviews to adjust permissions as roles change. The described approach in the best statement directly embodies this idea by restricting access to what’s necessary. The other statements miss the point: granting broad access for convenience undermines security, eliminating encryption is not related to privileges and weakens protection, and replacing audits with something else ignores ongoing accountability and monitoring essential to security.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy