Courseiva
easyMultiple ChoiceObjective-mapped

FC0-U71 Which security principle is being applied? Practice Question

Exhibit

Refer to the exhibit.
Firewall Rule:
Source IP: 192.168.1.0/24
Destination IP: 10.0.0.0/8
Protocol: TCP
Port: 22
Action: Allow

Which security principle is being applied?

⚠ Common exam trap

CompTIA often tests least privilege by presenting a scenario where a user has more access than needed, and candidates confuse it with 'need to know'—the trap is that need to know applies to data access based on job necessity, while least privilege applies to all permissions (including system functions and files).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Least privilege

The principle of least privilege ensures that users or systems are granted only the minimum permissions necessary to perform their tasks. By granting only what is required, the attack surface is reduced, limiting potential damage from compromised accounts or accidental misuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Least privilege

    Why this is correct

    Least privilege grants only the minimal necessary access; this rule restricts SSH to only the required subnet.

  • Need to know

    Why it's wrong here

    Need to know restricts access to data, not network traffic.

  • Separation of duties

    Why it's wrong here

    Separation of duties divides responsibilities to prevent fraud, not network access.

  • Defense in depth

    Why it's wrong here

    Defense in depth uses multiple layers, but this rule is a single layer.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

5 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to implement the principle of least privilege for its employees. Which TWO of the following actions align with this principle? (Choose TWO.)

medium
  • A.Providing access only to the applications needed for each employee's role
  • B.Allowing employees to share passwords for convenience
  • C.Granting all employees administrative rights by default
  • D.Revoking access to systems when an employee changes roles
  • E.Giving all employees full access to the company's financial data

Why A: Least privilege means giving users only the permissions necessary to perform their jobs. Granting access only to required applications and revoking old permissions enforce this.

Variation 2. Which of the following best describes the principle of least privilege?

medium
  • A.Access should be granted based on seniority within the organization.
  • B.All users should have the same level of access to ensure consistency.
  • C.Users should have the minimum access needed to perform their tasks.
  • D.Users should have full administrative access to their own devices.

Why C: The principle of least privilege grants users only the permissions necessary to perform their job functions, minimizing potential damage from accidents or attacks.

Variation 3. An organization wants to ensure that employees only have access to the data necessary to perform their job functions. Which principle should be applied?

medium
  • A.Defense in depth
  • B.Separation of duties
  • C.Mandatory access control
  • D.Least privilege

Why D: The principle of least privilege grants users only the permissions they need to do their work, minimizing potential damage.

Variation 4. An organization uses a security model where users are granted the minimum permissions necessary to perform their job functions. This model is known as:

hard
  • A.Role-based access control
  • B.Principle of least privilege
  • C.Mandatory access control
  • D.Discretionary access control

Why B: The principle of least privilege ensures users have only the access they need, reducing risk of misuse.

Variation 5. Which of the following best describes the principle of least privilege?

easy
  • A.Users should have all permissions by default
  • B.Users should have the minimum permissions needed to do their job
  • C.Users should use multi-factor authentication
  • D.Users should change passwords every 30 days

Why B: The principle of least privilege states that users should be granted only the minimum permissions necessary to perform their job functions, reducing potential damage from accidents or attacks.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.