NivaarExam PrepOfficial exam papers ↗

19-Soft-B3 Security · May 2014

Question 7 of 7: Least Privilege, Defense in Depth, and Separation of Privilege

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams, May 2014 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.

Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control, Least Privilege), Ch. 1 & 9 (Defense in Depth, Separation of Duty).

Question 7: Least Privilege, Defense in Depth, and Separation of Privilege (20 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Part a) — the principle of least privilege. The principle of least privilege states that every user, process, or system component should be granted only the minimum set of permissions and access it needs to perform its legitimate function — nothing more, and only for as long as it is needed. For example, a web application's database account used to display a product catalogue should have SELECT-only access to the catalogue tables, not full read/write/delete access to the entire database. The benefit is containment: if that account, process, or user is compromised or misused (accidentally or maliciously), the resulting damage is limited to whatever that minimal privilege set allows, rather than extending to everything the broader system can do.

Part b) — defense in depth. Defense in depth is a security strategy of deploying multiple, independent, layered controls throughout a system rather than relying on any single mechanism to provide all the protection. Each layer (e.g. a network firewall, host-based intrusion detection, application-level input validation, encrypted storage, strong authentication, regular patching) is chosen so that if an attacker manages to bypass or defeat one layer, subsequent layers still stand between them and the protected asset. The rationale is that no single control is perfect — a firewall can be misconfigured, a patch can be late, a password can be phished — so security should never depend on one control being flawless; the layers are designed to fail independently rather than share a common weakness.

Part c) — separation of privilege. Separation of privilege (also called separation of duty) requires that a critical action or access to a sensitive resource depend on the cooperation of more than one independent credential, condition, or person, rather than any single one being sufficient on its own — for example, requiring two different administrators to each supply half of a decryption key before a system can be unlocked, or requiring one employee to initiate a large financial transfer and a second, different employee to approve it. This means that a single compromised credential, or a single dishonest or careless individual, is not by itself enough to complete the sensitive action — collusion or multiple independent failures are required, which is a substantially higher bar for an attacker (or an insider threat) to clear.

Back to the paper →