SY0-701 Security Program Management and Oversight Practice Question
A security administrator is implementing a new access control system and needs to ensure that users are granted only the permissions required to perform their job functions and nothing more. Which principle should guide the design of the access control system?
⚠ Common exam trap
Many candidates confuse least privilege with separation of duties, as both are access control principles, but only least privilege directly addresses minimizing permissions to job requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Least privilege is the principle that users should have only the minimum access rights required to perform their duties. This directly matches the administrator's objective to grant only necessary permissions. Separation of duties, MAC, and DAC are related but do not specifically ensure that permissions are restricted to job functions. Therefore, least privilege is the correct guiding principle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of duties
Why it's wrong here
Separation of duties is a principle that divides critical tasks among multiple users to prevent fraud or errors. While important, it does not directly address granting only necessary permissions; rather, it focuses on distributing responsibilities. The scenario explicitly asks for ensuring users have only the permissions required for their job, which is the definition of least privilege, not separation of duties.
- ✓
Least privilege
Why this is correct
The principle of least privilege requires that users are granted the minimum levels of access—or permissions—necessary to perform their job functions. This directly aligns with the administrator's goal to avoid excessive permissions. Implementing least privilege reduces the attack surface and limits potential damage from compromised accounts. It is a fundamental concept in access control design and should be the guiding principle in this scenario.
- ✗
Discretionary access control
Why it's wrong here
Discretionary access control (DAC) allows resource owners to grant permissions at their discretion. This model does not enforce least privilege by default and can lead to excessive permissions if owners are not careful. The scenario requires a principle that guides the design to restrict permissions to job needs, which is least privilege, not DAC.
- ✗
Mandatory access control
Why it's wrong here
Mandatory access control (MAC) is a model where access decisions are made based on security labels and clearances, not user discretion. It is a type of access control system, but it does not inherently ensure that users have only the permissions needed for their job. The principle described in the scenario is least privilege, which can be implemented within various access control models, including MAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Privacy by Design Principles
Key term
DAC
Discretionary Access Control is a security model where the owner of a resource decides who can access it and what permissions they have.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.