Open cardosec

Case 2DBBE6 · GRC · L1 Foundations

Least Privilege

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Grant only the minimum access needed for a task, for the minimum time. Limits blast radius of a compromised account.
  2. Implement with RBAC/ABAC, separate admin accounts, and just-in-time elevation (PIM/PAM) instead of standing admin.
  3. Privilege creep: movers keep old rights. Periodic access reviews (e.g. quarterly for privileged) catch it.
  4. Applies to machines too: scoped IAM roles, no wildcard Action/Resource policies, short-lived tokens.
  5. Pairs with separation of duties: no single person can both create and approve a payment or code deploy.

If the interviewer pushes back

  • How would you roll out least privilege in a cloud account where everyone already has AdministratorAccess?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.