StudyToCert

All certifications / A+ Core 2 / Lessons

CompTIA A+ Core 2 220-1202 · Domain 2: Security

Logical security: least privilege, zero trust, MFA methods (authenticator apps, SMS, hardware tokens, email), SSO, MDM, DLP, IAM, directory services, access control lists

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Logical security uses software and configuration, rather than locks and walls, to control who can use systems and data. Its starting principle is least privilege: give each user, service and device only the access it needs to do its job, and no more. A receptionist does not need administrator rights; a backup service account does not need to log on interactively. Least privilege limits the damage from mistakes, malware and stolen accounts, because whatever runs under an account can do only what that account can do.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 8 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study A+ Core 2 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the A+ Core 2 study plan