Grant only the access needed
Security+: Security Architecture
Original starter lesson / sources checked 2026-09-30
Least privilege gives a principal only the permissions required for its task. Authentication establishes identity; authorization decides allowed operations.
Use separate identities for routine and privileged work. Limit service-account scopes and avoid embedding private keys in browser bundles.
Review effective permissions and test denied operations. A hidden button cannot enforce access at the server or data layer.
Hands-on lab
- Write an access matrix for reader, editor, and administrator roles.
- List one allowed and one denied action for each role using a local test app.
Put the lesson to work
Original exam-style practice. Choose the best answer for the stated scenario.
Go deeper
Official CompTIA scope and exam informationWWADD Move: Keep secrets out of browser bundlesIndependent practice aligned to selected topics. No endorsement, actual exam items, or pass guarantee. Verify your exam version and use the full official objectives for complete preparation.