hardMultiple Choice
200-201 Practice Question: During a security audit, an analyst finds that a…
During a security audit, an analyst finds that a third-party vendor has access to sensitive customer data beyond what is necessary for their services. Which principle of least privilege should the policy enforce?
⚠ Common exam trap
200-201 often tests whether candidates confuse preventive controls (access control policies) with reactive ones (incident response) — the trap is picking the incident response plan when the question asks how to enforce least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce a data classification and access control policy
The principle of least privilege requires that users and third parties have only the minimum access necessary to perform their function. Enforcing a data classification and access control policy ensures sensitive customer data is categorized and that vendor access is restricted based on that classification, directly addressing excessive access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement an incident response plan for data leaks
Why it's wrong here
An incident response plan governs detection and containment after a breach; it does not limit the vendor's standing access to customer data. It is tempting because it addresses data leaks, and would be correct where the requirement is to define escalation, notification and recovery steps once unauthorised disclosure has occurred.
- ✗
Update the end-user license agreement
Why it's wrong here
Updating the end-user license agreement is a legal measure, not a technical control for enforcing least privilege.
- ✓
Enforce a data classification and access control policy
Why this is correct
Enforcing data classification with access control directly limits vendor permissions to only the sensitivity level their service requires, satisfying the least-privilege constraint. Classification tags data, and access control policies grant rights based on those tags, so vendors cannot reach sensitive customer data beyond their defined scope.
- ✗
Invoke a service-level agreement
Why it's wrong here
Invoking a service-level agreement addresses service performance, not access rights or the principle of least privilege.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.