Today’s 220-1202 CompTIA A+ Pop Quiz: What could go wrong

An IT intern has granted administrative rights to the entire company file server despite only requiring image uploads to a specific folder. Which security principle is being violated in this configuration?