Case 2DBBE6 · GRC · L1 Foundations
Least Privilege
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Grant only the minimum access needed for a task, for the minimum time. Limits blast radius of a compromised account.
- Implement with RBAC/ABAC, separate admin accounts, and just-in-time elevation (PIM/PAM) instead of standing admin.
- Privilege creep: movers keep old rights. Periodic access reviews (e.g. quarterly for privileged) catch it.
- Applies to machines too: scoped IAM roles, no wildcard Action/Resource policies, short-lived tokens.
- Pairs with separation of duties: no single person can both create and approve a payment or code deploy.
If the interviewer pushes back
- How would you roll out least privilege in a cloud account where everyone already has AdministratorAccess?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.