Courseiva
Security →hardMultiple Choice

FC0-U71 Security Practice Question

A security analyst is reviewing access logs and notices that an employee in the marketing department was able to read files in the human resources shared folder. The employee's account should only have access to marketing resources. Which security principle was violated?

⚠ Common exam trap

Many exam-takers confuse least privilege with separation of duties, which is about dividing tasks to prevent fraud, not about limiting access to data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

The principle of least privilege states that users should be granted only the access required for their role. The marketing employee reading HR files indicates excessive permissions. Separation of duties, defense in depth, and zero trust are related concepts but do not directly name the violation of over-provisioned access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Zero trust

    Why it's wrong here

    Zero trust is a model that assumes no implicit trust and verifies every access request. Although a zero trust architecture would help prevent this, the specific violation is that the user had excessive permissions. Zero trust is a broader framework, not the name of the principle that was directly breached in this access control failure.

  • ✓

    Least privilege

    Why this is correct

    Least privilege means users should have only the minimum access necessary to perform their job. The marketing employee was able to read HR files, which is beyond their required access. This violation of least privilege can lead to data exposure and is a common finding in access control audits.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties ensures that no single person has control over all parts of a critical process, such as approving and executing a transaction. The scenario describes excessive access rights, not a lack of task separation. The employee did not perform conflicting duties; they simply had unauthorized read access to another department's files.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth is a layered security strategy using multiple controls. While excessive access might be mitigated by additional layers, the core issue here is that the account had more permissions than needed. The scenario does not indicate a failure of multiple layers, but rather a failure to restrict permissions appropriately.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.