hardMultiple Select
FC0-U71 Practice Question: A database administrator is setting up user…
A database administrator is setting up user permissions. Which THREE actions follow the principle of least privilege?
⚠ Common exam trap
It's easy for candidates to confuse 'flexibility' (Option C) or 'convenience' (Option D) with good security practice, failing to recognize that least privilege requires minimizing access, not maximizing it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Granting SELECT only on specific tables to a read-only user
Option A is correct because granting SELECT only on specific tables to a read-only user limits that user to exactly the data they need to read, with no ability to modify or access unrelated objects, which is the essence of least privilege. Option B is correct because revoking INSERT and DELETE from a user who only needs to view data removes unnecessary write permissions, ensuring the account cannot alter or remove records beyond its required read-only function. Option E is correct because granting access to a specific database schema rather than the entire server scopes permissions to the minimum required container, preventing the user from touching other schemas or server-level resources. Option C does not belong because allowing remote access from any IP address broadens the attack surface and violates least privilege, which would instead restrict access to specific trusted hosts or networks. Option D does not belong because granting DBA privileges to all developers for convenience gives far more authority than any development task requires, directly contradicting least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Granting SELECT only on specific tables to a read-only user
Why this is correct
SELECT on named tables grants only the read capability the role requires, with no write, schema or server-level rights. This matches the principle of least privilege by scoping permissions to the minimum data set needed for the read-only function.
- ✓
Revoking INSERT and DELETE from a user who only needs to view data
Why this is correct
Revoking INSERT and DELETE leaves only SELECT, matching the "view data" requirement exactly. Least privilege grants the minimum access necessary, so removing write capabilities the user never needs eliminates accidental or malicious modification while preserving read access. This directly satisfies the stem's constraint of a user who only needs to view data.
- ✗
Allowing remote access from any IP address for flexibility
Why it's wrong here
Opening remote access to any IP address abandons source-address restriction, so credentials alone guard the database. Least privilege scopes access to known networks or specific hosts. It is tempting because unrestricted connectivity removes firewall troubleshooting, and it would suit a public, non-sensitive test endpoint where convenience outweighs exposure.
- ✗
Granting DBA privileges to all developers for convenience
Why it's wrong here
Handing DBA rights to every developer grants full schema, data and permission control far beyond coding needs, violating least privilege. Developers should receive scoped read/write roles. It is tempting because shared DBA accounts remove permission requests, and it would fit a small isolated development sandbox with disposable, non-production data.
- ✓
Granting access to a specific database schema rather than the entire server
Why this is correct
Schema-level grants confine access to the relevant objects rather than exposing every database on the server. This satisfies least privilege by limiting the permission boundary to the smallest scope that still supports the user's work.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.