careers / security / least privilege
Security foundations path

Grant only the access needed

Security+: Security Architecture
Original starter lesson / sources checked 2026-09-30

Least privilege gives a principal only the permissions required for its task. Authentication establishes identity; authorization decides allowed operations.

Use separate identities for routine and privileged work. Limit service-account scopes and avoid embedding private keys in browser bundles.

Review effective permissions and test denied operations. A hidden button cannot enforce access at the server or data layer.

Hands-on lab

  1. Write an access matrix for reader, editor, and administrator roles.
  2. List one allowed and one denied action for each role using a local test app.

Put the lesson to work

Original exam-style practice. Choose the best answer for the stated scenario.

1. A reporting service only reads one dataset. Which permission model best follows least privilege?
2. An authenticated user attempts to delete another user's record. What control decides whether the operation is allowed?

Go deeper

Official CompTIA scope and exam informationWWADD Move: Keep secrets out of browser bundles

Independent practice aligned to selected topics. No endorsement, actual exam items, or pass guarantee. Verify your exam version and use the full official objectives for complete preparation.

WWADD — Choose the tool. Make the move. Build the stack.

FREE REFERENCE · NO LOGINCONTACTPRIVACYTERMS