Courseiva
hardMultiple Select

FC0-U71 Practice Question: A database administrator is setting up user…

A database administrator is setting up user permissions. Which THREE actions follow the principle of least privilege?

⚠ Common exam trap

It's easy for candidates to confuse 'flexibility' (Option C) or 'convenience' (Option D) with good security practice, failing to recognize that least privilege requires minimizing access, not maximizing it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Granting SELECT only on specific tables to a read-only user

Option A is correct because granting SELECT only on specific tables to a read-only user limits that user to exactly the data they need to read, with no ability to modify or access unrelated objects, which is the essence of least privilege. Option B is correct because revoking INSERT and DELETE from a user who only needs to view data removes unnecessary write permissions, ensuring the account cannot alter or remove records beyond its required read-only function. Option E is correct because granting access to a specific database schema rather than the entire server scopes permissions to the minimum required container, preventing the user from touching other schemas or server-level resources. Option C does not belong because allowing remote access from any IP address broadens the attack surface and violates least privilege, which would instead restrict access to specific trusted hosts or networks. Option D does not belong because granting DBA privileges to all developers for convenience gives far more authority than any development task requires, directly contradicting least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Granting SELECT only on specific tables to a read-only user

    Why this is correct

    SELECT on named tables grants only the read capability the role requires, with no write, schema or server-level rights. This matches the principle of least privilege by scoping permissions to the minimum data set needed for the read-only function.

  • ✓

    Revoking INSERT and DELETE from a user who only needs to view data

    Why this is correct

    Revoking INSERT and DELETE leaves only SELECT, matching the "view data" requirement exactly. Least privilege grants the minimum access necessary, so removing write capabilities the user never needs eliminates accidental or malicious modification while preserving read access. This directly satisfies the stem's constraint of a user who only needs to view data.

  • ✗

    Allowing remote access from any IP address for flexibility

    Why it's wrong here

    Opening remote access to any IP address abandons source-address restriction, so credentials alone guard the database. Least privilege scopes access to known networks or specific hosts. It is tempting because unrestricted connectivity removes firewall troubleshooting, and it would suit a public, non-sensitive test endpoint where convenience outweighs exposure.

  • ✗

    Granting DBA privileges to all developers for convenience

    Why it's wrong here

    Handing DBA rights to every developer grants full schema, data and permission control far beyond coding needs, violating least privilege. Developers should receive scoped read/write roles. It is tempting because shared DBA accounts remove permission requests, and it would fit a small isolated development sandbox with disposable, non-production data.

  • ✓

    Granting access to a specific database schema rather than the entire server

    Why this is correct

    Schema-level grants confine access to the relevant objects rather than exposing every database on the server. This satisfies least privilege by limiting the permission boundary to the smallest scope that still supports the user's work.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.