Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician discovers that a junior colleague has been using a domain administrator account to perform routine user tasks such as resetting passwords and installing software. Which security principle is being violated?

⚠ Common exam trap

Many exam-takers confuse 'privileged account management' with 'role-based access control' (RBAC), but RBAC is about assigning permissions based on roles, whereas the core issue is the failure to restrict the use of a highly privileged account to only necessary tasks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged account management

Using a domain administrator account for routine tasks violates privileged account management because it fails to enforce the principle of least privilege. Domain admin credentials should only be used for tasks that require elevated privileges, such as schema modifications or domain controller configuration, not for everyday operations like password resets or software installations. This practice increases the risk of credential misuse and lateral movement if the account is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties is a control designed to prevent fraud and errors by requiring multiple individuals to complete critical tasks, such as one person authorizing a purchase and another approving payment. It does not directly address the scenario of a domain administrator using elevated privileges for routine work. The violation here stems from using the wrong account type for the task, not from concentrating conflicting responsibilities in one role.

  • ✗

    Role-based access control

    Why it's wrong here

    Role-based access control (RBAC) is an access control model that assigns permissions based on an employee's job function, such as granting helpdesk staff password-reset rights. While least privilege is an underlying goal of RBAC, the violation in this scenario is not that permissions were assigned incorrectly by role; it is that an account with domain administrator privileges was used for non-administrative work. RBAC describes how roles map to permissions, but the problem is the operational failure to switch to a standard, unprivileged account for routine activities.

  • ✓

    Privileged account management

    Why this is correct

    Privileged account management (PAM) encompasses the policies, processes, and tools that govern the lifecycle of highly privileged accounts like domain administrators, including enforcing that such accounts are used only for elevated administrative tasks. Using a domain administrator account for everyday activities such as checking email or browsing the web violates least privilege and expands the attack surface, because a compromise of that session would yield domain-wide control. PAM mitigates this by enforcing credential vaulting, session monitoring, Just-In-Time elevation, and requiring users to log on with standard accounts for regular work.

  • ✗

    Audit logging

    Why it's wrong here

    Audit logging is a detective control that records authentication attempts, command execution, and other security-relevant events to provide a trail for incident investigations and compliance. It does not prevent an administrator from misusing a privileged account; it simply captures evidence of the misuse after the fact. While enabling audit logging is crucial for detecting such violations, it is not the principle or policy that would have stopped the junior colleague from using the domain admin account for routine tasks.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.