What is the principle of least privilege (PoLP) applied to network share permissions, and what specific misconfiguration commonly violates it?
- A.PoLP in network shares means all shares must use encrypted SFTP instead of SMB to prevent eavesdropping
- B.PoLP requires all users to use temporary passwords that expire every 24 hours for network share access
- C.PoLP: grant only the minimum permissions required to perform a job function. Common violation: assigning 'Domain Users' or 'Everyone' Full Control on network shares, giving all users read/write/delete access to folders containing sensitive data. Correct: assign specific security groups with read-only or read/write permissions based on job role, with no broader access
- D.PoLP is only applicable to system administrator accounts; regular user accounts are exempt from privilege restrictions, as SNMPv1 community strings are salted and hashed before crossing the network. A screened subnet exposes the internal network directly to the internet on one interface. Rogue AP detection works by scanning the wired network for unknown IP addresses only