TechKnowSurge
NIST 800-53 AC-6 NIST CSF PR.AA-05 ISC2 CC 3.2 NIST 800-53 AC-5
InteractiveSecurityFree

Permission Trimmer

Trim three over-permissioned accounts down to what each job needs, then split a vendor payment and an access request so no one person controls the whole process.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

More like this

About this interactive

What you’re seeing: two short jobs, one for each access control principle from the lesson. First, three employee accounts that were handed every permission in the company. Your job is to switch off whatever each person’s role does not need, and each permission then tells you why it stays or what it would expose. Second, two sensitive processes, paying a vendor and granting access to a folder, where you decide who does each step. Why it matters: least privilege and separation of duties are both about limiting access, but they stop different problems. Least privilege shrinks what one account can reach, so a stolen password or a careless click does less damage. Separation of duties makes sure no single person can start, approve and complete something like a payment, which is what stops one employee from inventing a fake vendor and paying it. How to use it: read each job description before touching a switch, and in Part 2 watch for the conflict warning. It appears the moment one person holds two steps that should never be held together.

How to play

Part 1 — Least privilege. Three employees each have an account with every permission switched on. Read the job description, then switch off everything the job does not need and check the account. You get one check per account, and every permission explains why it stays or goes.

Part 2 — Separation of duties. Assign a person to each step of two sensitive processes. Nobody may both start a transaction and approve or complete it. A warning appears as soon as one person holds a conflicting pair.

Each part is half your score, so both principles count. Reach 80% to earn the flag.

What you'll learn

Aligned to

NIST 800-53
AC-6 Least Privilege
AC-5 Separation of Duties
NIST CSF
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
ISC2 CC
3.2 Understand logical access controls

Key terms

Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.
Permissions
The defined access rights granted to users, groups, or objects that control what resources they can access or modify.
Fraud
Intentional deception or misrepresentation carried out for financial gain, such as embezzlement or falsifying records.

Topics

Interactive Least Privilege Separation Of Duties Permissions Access Control Fraud

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →