FC0-U71 Security Practice Question
A security analyst is reviewing access logs and notices that an employee in the marketing department was able to read files in the human resources shared folder. The employee's account should only have access to marketing resources. Which security principle was violated?
⚠ Common exam trap
Many exam-takers confuse least privilege with separation of duties, which is about dividing tasks to prevent fraud, not about limiting access to data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
The principle of least privilege states that users should be granted only the access required for their role. The marketing employee reading HR files indicates excessive permissions. Separation of duties, defense in depth, and zero trust are related concepts but do not directly name the violation of over-provisioned access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Zero trust
Why it's wrong here
Zero trust is a model that assumes no implicit trust and verifies every access request. Although a zero trust architecture would help prevent this, the specific violation is that the user had excessive permissions. Zero trust is a broader framework, not the name of the principle that was directly breached in this access control failure.
- ✓
Least privilege
Why this is correct
Least privilege means users should have only the minimum access necessary to perform their job. The marketing employee was able to read HR files, which is beyond their required access. This violation of least privilege can lead to data exposure and is a common finding in access control audits.
- ✗
Separation of duties
Why it's wrong here
Separation of duties ensures that no single person has control over all parts of a critical process, such as approving and executing a transaction. The scenario describes excessive access rights, not a lack of task separation. The employee did not perform conflicting duties; they simply had unauthorized read access to another department's files.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a layered security strategy using multiple controls. While excessive access might be mitigated by additional layers, the core issue here is that the account had more permissions than needed. The scenario does not indicate a failure of multiple layers, but rather a failure to restrict permissions appropriately.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.