Module 4
Least Privilege in Practice
Five findings from security reviews, each one a rule that was correct when it was written and grants more than anyone now intends.
In this module
- Narrow an over-broad rule without breaking what depends on it
- Grant a contractor access to exactly one system
- Audit what a segment can actually reach, rather than what it should
Activities
Overly broad firewall rule
Guest wifi reaching payroll, via a rule nobody reread.
Contractor limited access
One server, nothing else, expressed as a rule.
Audit the IoT VLAN's reach
Confirming a segment reaches only what it is supposed to.
Web tier bypasses the app tier
A permitted path that skips a layer it was meant to go through.
Divested business separation
Two companies in one building, sharing no network access.
Sign in to take the knowledge checks, run the labs and track your progress.
Curriculum topics
Each topic page lists every lesson, quiz and hands-on lab that covers it, plus how it maps onto the CCNA and Network+ blueprints.
