Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security analyst reviews logs after a ransomware incident. The infection started on a user's workstation and spread to network shares using the user's credentials. The user had been granted local administrator rights on their workstation six months ago for a software installation, and the rights were never removed. Which security principle was most directly violated?

⚠ Common exam trap

Candidates often confuse 'least privilege' with 'separation of duties' because both involve access control, but least privilege focuses on the minimum rights needed for a role, while separation of duties is about splitting responsibilities to prevent a single person from having too much control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

B. Least privilege

The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. In this scenario, the user retained local administrator rights long after the software installation was completed, which allowed the ransomware to execute with elevated privileges and use the user's credentials to spread to network shares. This direct violation of least privilege enabled the lateral movement and broader impact of the attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A. Separation of duties

    Why it's wrong here

    Separation of duties is a control designed to prevent fraud and errors by requiring more than one person to complete a critical task, such as separating the roles of system administrator and auditor. In this incident, the issue is not that responsibilities were split or combined improperly, but that a single account retained elevated rights after a specific task. Thus, separation of duties does not address the root cause of excessive permissions remaining active.

  • ✓

    B. Least privilege

    Why this is correct

    Least privilege is the security principle that grants users only the permissions necessary to perform their current job functions and nothing more. In this scenario, the user was given administrative rights for a specific installation, but those rights were not revoked afterwards, leaving the account with unnecessary elevated access. This directly contradicts least privilege by maintaining standing admin rights, which increases the attack surface and enables ransomware to execute with high privileges. The proper remediation is to grant temporary elevation and remove it immediately after the task is complete.

  • ✗

    C. Job rotation

    Why it's wrong here

    Job rotation is a personnel management practice that periodically moves employees among different roles or functions to reduce the risk of collusion, boredom, or long-term insider threats. It is unrelated to permission levels or how many rights a user holds in a given role. While job rotation can help detect anomalies over time, it would not have prevented this specific ransomware incident caused by an account retaining excessive permissions.

  • ✗

    D. Mandatory access control

    Why it's wrong here

    Mandatory access control (MAC) is a system-enforced access model that uses sensitivity labels (e.g., confidential, secret) and clearance levels to govern access, rather than a user's or administrator's discretion. MAC does not address the problem of a user having too many privileges for a given role; it focuses on classification labeling and strict system policies, such as those in SELinux or Apple's TCC. The issue here is a failure to apply the least privilege concept, not a lack of label-based controls.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.