Courseiva

SY0-701 Security Program Management and Oversight Practice Question

A security administrator is implementing a new access control system and needs to ensure that users are granted only the permissions required to perform their job functions and nothing more. Which principle should guide the design of the access control system?

⚠ Common exam trap

Many candidates confuse least privilege with separation of duties, as both are access control principles, but only least privilege directly addresses minimizing permissions to job requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

Least privilege is the principle that users should have only the minimum access rights required to perform their duties. This directly matches the administrator's objective to grant only necessary permissions. Separation of duties, MAC, and DAC are related but do not specifically ensure that permissions are restricted to job functions. Therefore, least privilege is the correct guiding principle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties is a principle that divides critical tasks among multiple users to prevent fraud or errors. While important, it does not directly address granting only necessary permissions; rather, it focuses on distributing responsibilities. The scenario explicitly asks for ensuring users have only the permissions required for their job, which is the definition of least privilege, not separation of duties.

  • ✓

    Least privilege

    Why this is correct

    The principle of least privilege requires that users are granted the minimum levels of access—or permissions—necessary to perform their job functions. This directly aligns with the administrator's goal to avoid excessive permissions. Implementing least privilege reduces the attack surface and limits potential damage from compromised accounts. It is a fundamental concept in access control design and should be the guiding principle in this scenario.

  • ✗

    Discretionary access control

    Why it's wrong here

    Discretionary access control (DAC) allows resource owners to grant permissions at their discretion. This model does not enforce least privilege by default and can lead to excessive permissions if owners are not careful. The scenario requires a principle that guides the design to restrict permissions to job needs, which is least privilege, not DAC.

  • ✗

    Mandatory access control

    Why it's wrong here

    Mandatory access control (MAC) is a model where access decisions are made based on security labels and clearances, not user discretion. It is a type of access control system, but it does not inherently ensure that users have only the permissions needed for their job. The principle described in the scenario is least privilege, which can be implemented within various access control models, including MAC.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.