A desktop support technician is creating a standard user account for an employee who only needs to run office productivity software and browse approved intranet sites. According to the principle of least privilege, which of the following permission assignments is MOST appropriate for this user?
Select one.
Make the user a local administrator to allow software installation without assistance
Disable the account lockout policy so the user is never locked out
Grant the user only the permissions necessary to perform assigned job tasks
Give all users full control of their workstation to reduce help-desk workload
The principle of least privilege states that users should receive only the minimum permissions required to accomplish their job duties and nothing more. Assigning a standard (non-administrator) account with only the rights needed to run approved applications satisfies this best practice. Granting administrator rights, providing unrestricted control, or weakening security policies would violate the principle and increase risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the different types of database systems used for asset management?
Open an interactive chat with Bash
How does a database system ensure the accuracy of asset tracking?
Open an interactive chat with Bash
What role does user information management play in a database system for asset management?