Certified Information Systems Security Professional – CISSP – Question198

Which of the following BEST represents the concept of least privilege?

A.
Access to an object is denied unless access is specifically allowed.
B. Access to an object is only available to the owner.
C. Access to an object is allowed unless it is protected by the information security policy.
D. Access to an object is only allowed to authenticated users via an Access Control List (ACL).

Correct Answer: A