220-1102 Security Practice Question
A security analyst reviews logs after a ransomware incident. The infection started on a user's workstation and spread to network shares using the user's credentials. The user had been granted local administrator rights on their workstation six months ago for a software installation, and the rights were never removed. Which security principle was most directly violated?
⚠ Common exam trap
Candidates often confuse 'least privilege' with 'separation of duties' because both involve access control, but least privilege focuses on the minimum rights needed for a role, while separation of duties is about splitting responsibilities to prevent a single person from having too much control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
B. Least privilege
The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. In this scenario, the user retained local administrator rights long after the software installation was completed, which allowed the ransomware to execute with elevated privileges and use the user's credentials to spread to network shares. This direct violation of least privilege enabled the lateral movement and broader impact of the attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A. Separation of duties
Why it's wrong here
Separation of duties is a control designed to prevent fraud and errors by requiring more than one person to complete a critical task, such as separating the roles of system administrator and auditor. In this incident, the issue is not that responsibilities were split or combined improperly, but that a single account retained elevated rights after a specific task. Thus, separation of duties does not address the root cause of excessive permissions remaining active.
- ✓
B. Least privilege
Why this is correct
Least privilege is the security principle that grants users only the permissions necessary to perform their current job functions and nothing more. In this scenario, the user was given administrative rights for a specific installation, but those rights were not revoked afterwards, leaving the account with unnecessary elevated access. This directly contradicts least privilege by maintaining standing admin rights, which increases the attack surface and enables ransomware to execute with high privileges. The proper remediation is to grant temporary elevation and remove it immediately after the task is complete.
- ✗
C. Job rotation
Why it's wrong here
Job rotation is a personnel management practice that periodically moves employees among different roles or functions to reduce the risk of collusion, boredom, or long-term insider threats. It is unrelated to permission levels or how many rights a user holds in a given role. While job rotation can help detect anomalies over time, it would not have prevented this specific ransomware incident caused by an account retaining excessive permissions.
- ✗
D. Mandatory access control
Why it's wrong here
Mandatory access control (MAC) is a system-enforced access model that uses sensitivity labels (e.g., confidential, secret) and clearance levels to govern access, rather than a user's or administrator's discretion. MAC does not address the problem of a user having too many privileges for a given role; it focuses on classification labeling and strict system policies, such as those in SELinux or Apple's TCC. The issue here is a failure to apply the least privilege concept, not a lack of label-based controls.
Go deeper
Related to this question
Learn chapter
MFA Types for Users
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.