Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is reviewing the access control strategy for a research and development department. The department handles highly sensitive intellectual property, and the organization wants to ensure that employees can only access information strictly necessary for their current project tasks, even if they have previously worked on other projects. Which access control principle is being enforced?

⚠ Common exam trap

Many exam-takers confuse need to know with least privilege, as both limit access, but need to know is specifically about information relevance to a task, while least privilege is about minimum permissions for a role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Need to know

The need-to-know principle ensures that access to information is granted only to individuals whose current responsibilities require that specific information. In this scenario, the organization wants to restrict access to intellectual property based on project tasks, which directly reflects need-to-know. Least privilege is about minimum permissions, but need-to-know is more granular and focuses on information relevance to the task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mandatory access control

    Why it's wrong here

    Mandatory access control is a system-enforced access policy based on security labels and clearances, often used in government or military contexts. It does not typically adapt to project-specific needs; instead, it uses fixed classification levels. The scenario describes a business context focused on project-based access, not a label-based system.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties divides a critical task among multiple people to prevent fraud or error, such as requiring two approvals for a financial transaction. It does not limit data access based on project necessity; it restricts task completion. In this scenario, the goal is to limit access to information based on current project needs, not to split a single task across multiple users.

  • ✓

    Need to know

    Why this is correct

    Need to know restricts access to information only to individuals who require it to perform their specific duties. In this scenario, employees should only access data necessary for their current project tasks, aligning with the need-to-know principle. It ensures that even if an employee had access to other projects previously, that access is revoked when no longer needed.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege grants users the minimum permissions needed to perform their job functions, but it does not inherently account for dynamic project assignments or historical access. It is a broader principle about permission levels, not about restricting access based on current task necessity. The scenario specifically emphasizes need-to-know for a project, which is a more granular concept.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.