Least functionality
Configuring a system to provide only the functions, ports, protocols, software and services its mission requires, and disabling or removing the rest to reduce the attack surface.
Least functionality is the configuration principle that a system should offer only what it needs to do its job. NIST SP 800-53 Rev. 5 sets it out as control CM-7, which asks organisations to configure systems to provide only mission-essential capabilities and to prohibit or restrict functions, ports, protocols, software and services that are not required. A web server that also runs a file-sharing service, a mail relay and a remote desktop listener nobody uses carries three extra ways in, each of which needs patching and monitoring.
The principle is easily confused with least privilege. Least privilege limits the rights given to users, processes and accounts; least functionality limits the capabilities a system offers in the first place. Least functionality is also the reasoning behind much of hardening: removing unneeded packages, closing ports and disabling services are how the principle is put into practice, and the resulting configuration is usually recorded in a security baseline. Application allow-listing, which lets only approved software run, appears as an enhancement to the same control.
Exam relevance: a scenario may describe a system running services nobody uses and ask which principle it breaks. Candidates are expected to tell least functionality (what the system can do) apart from least privilege (what a subject is allowed to do).