StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 2: Threats, vulnerabilities & mitigations

Least privilege, access control lists

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

The principle of least privilege says that every user, process and system should have only the access it needs to do its job, and no more, for only as long as it needs it. It matters because excess access turns small incidents into large ones: if a phished user is a local administrator, the malware runs as administrator; if a web application's database account can drop tables, a SQL injection flaw can destroy data. Least privilege does not stop every attack, but it limits the blast radius of the attacks that succeed.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan