ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 9 - SY0-701 discussion

Report
Export

Which of the following security concepts is the best reason for permissions on a human resources fileshare to follow the principle of least privilege?

A.
Integrity
Answers
A.
Integrity
B.
Availability
Answers
B.
Availability
C.
Confidentiality
Most voted
Answers (4)
Most voted
C.
Confidentiality
D.
Non-repudiation
Answers
D.
Non-repudiation
Suggested answer: C

Explanation:

Confidentiality is the security concept that ensures data is protected from unauthorized access or disclosure. The principle of least privilege is a technique that grants users or systems the minimum level of access or permissions that they need to perform their tasks, and nothing more. By applying the principle of least privilege to a human resources fileshare, the permissions can be restricted to only those who have a legitimate need to access the sensitive data, such as HR staff, managers, or auditors. This can prevent unauthorized users, such as hackers, employees, or contractors, from accessing, copying, modifying, or deleting the data. Therefore, the principle of least privilege can enhance the confidentiality of the data on the fileshare. Integrity, availability, and non-repudiation are other security concepts, but they are not the best reason for permissions on a human resources fileshare to follow the principle of least privilege. Integrity is the security concept that ensures data is accurate and consistent, and protected from unauthorized modification or corruption. Availability is the security concept that ensures data is accessible and usable by authorized users or systems when needed. Non-repudiation is the security concept that ensures the authenticity and accountability of data and actions, and prevents the denial of involvement or responsibility. While these concepts are also important for data security, they are not directly related to the level of access or permissions granted to users or systems.

Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 16-17, 372-373

asked 02/10/2024
Ricardo Chapa
40 questions
User
Your answer:
4 comments
Sorted by
Up
0
Down
User
stephanie bagcal

Edited 8 days ago

Voted C

answer c

Reply
Reply
Report

Up
0
Down
User
Jennifer Leon

Edited 19 days ago

Voted C

I choose C. It refers to ensuring that sensitive information is only accessible to individuals who have the appropriate clearance or need-to-know

Reply
Reply
Report

Up
0
Down
User
Bruno Soriano

Edited 19 days ago

Voted C

C - Confidentiality ensures that sensitive information is only accessible to those who are authorized to view it.

Reply
Reply
Report

Up
0
Down
User
DANIEL DOYEN

Edited 19 days ago

Voted C

C correct

Reply
Reply
Report