ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a code-review of an analytics platform, you discover that every data analyst logs in through a single database account with read permission to all schemas. Which change would most directly apply the need-to-know aspect of least privilege for these analysts?
Move the production database to a read-only replica that all analysts can query, keeping the shared account.
Require analysts to justify access in the ticketing system but still authenticate through the common account.
Enable transparent data encryption on every tablespace while continuing to use the shared account for access.
Issue each analyst a personal account restricted to only the specific schemas they require and set the grants to expire after the project milestone.
Need-to-know limits access to the exact information a person requires and no more. Issuing each analyst a unique account that is restricted to only the schemas they actively support enforces that principle; it prevents them from viewing data outside their job scope and permits easy revocation when their role or project ends. Simply moving data to a replica, adding encryption, or requiring justification without changing the overly broad shared credential all leave universal access in place, so they do not satisfy need-to-know.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege?
Open an interactive chat with Bash
Why is logging in with shared accounts a security risk?
Open an interactive chat with Bash
How do schema-level permissions enhance data security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .