Multiple choice technology security

The principle of least privilege as it applies to Access control mandates that:

  1. Group based access control should be implemented to assign permissions to application users

  2. Consistent authorization checking should be performed on all application pages

  3. A set of all allowable actions should be defined for each user role and all other's denied

  4. All failed access authorization requests should be logged to a secure location for review by administrators

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

The principle of least privilege means users should have only the minimum permissions necessary to perform their job functions. Option C correctly implements this by defining allowable actions for each role and denying everything else. Group-based access (A) is a method but doesn't define the principle, consistent checking (B) is about authorization implementation, and logging (D) is about audit trails.