システム オペレータには、監視アプリケーション、構成アプリケーション、および時間管理アプリケーションへのアクセスが許可されます。オペレーターは、システムのセキュリティ構成によって財務およびプロジェクト管理アプリケーションへのアクセスを拒否されます。次のうち、使用中のセキュリティ原則を最もよく表しているのはどれですか?
正解:B
The security principle of least privilege states that users or processes should only have the minimum level of access or permissions required to perform their tasks. This reduces the risk of unauthorized or malicious actions, as well as the impact of potential breaches. In this scenario, the systems operator is granted access to only the applications that are relevant to their role, and denied access to the applications that are not. This is an example of applying the least privilege principle. Reference:
CompTIA Network+ N10-008 Certification Study Guide, Chapter 7: Network Security Concepts and Tools, Section 7.1: Common Security Concepts, Subsection: Least Privilege1 Professor Messer's CompTIA N10-008 Network+ Course, Section 7.1: Common Security Concepts, Video: Least Privilege2