FC0-U71 Security Practice Question
A company wants to implement the principle of least privilege for its employees. Which TWO of the following actions align with this principle? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Providing access only to the applications needed for each employee's role
Option A is correct because least privilege means granting each user only the minimum access required to perform their job, so providing access only to the applications needed for each employee's role directly enforces that restriction. Option D is correct because least privilege requires continuously right-sizing permissions; revoking access when an employee changes roles prevents privilege accumulation and removes rights no longer needed for the new position. Option B is not correct because sharing passwords destroys individual accountability and grants access beyond what any single user should have. Option C is not correct because granting administrative rights by default massively exceeds the minimum necessary privileges. Option E is not correct because giving everyone full access to financial data violates least privilege by exposing sensitive data to users who do not need it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Providing access only to the applications needed for each employee's role
Why this is correct
Least privilege grants each user only the access required for their duties. Restricting applications to those needed for a specific role directly enforces that minimum-access principle, satisfying the stem's requirement for actions that align with least privilege.
- ✗
Allowing employees to share passwords for convenience
Why it's wrong here
Shared passwords destroy individual accountability and grant every holder the accumulated access of all users, exceeding each person's required permissions. It is tempting because sharing appears to reduce helpdesk overhead, and would be correct only where no attribution or segregation of duties is required, which least privilege never permits.
- ✗
Granting all employees administrative rights by default
Why it's wrong here
Default administrative rights give every employee far more privilege than their duties demand, directly contradicting least privilege. It is tempting because blanket admin rights reduce permission-request tickets, and would be correct only in a lab or single-administrator environment where no separation of duties exists.
- ✓
Revoking access to systems when an employee changes roles
Why this is correct
Removing permissions when someone moves to a new role enforces least privilege by ensuring access matches current duties only. Stale entitlements from the previous position are revoked, preventing accumulated rights that exceed what the new role requires.
- ✗
Giving all employees full access to the company's financial data
Why it's wrong here
Full financial-data access for all staff grants permissions unrelated to most roles, violating least privilege. It is tempting because open access removes approval bottlenecks, and would be correct only if every employee genuinely required that data, which the principle explicitly rejects.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.