Applying Least Privilege to Help Desk Roles
A help desk analyst can reset passwords in the ticketing portal but cannot view payroll records, edit user profiles, or access other HR functions. Which security principle is the organization applying?
Quick Answer
The answer is least privilege. This security principle dictates that a help desk analyst should only have the minimum permissions necessary to perform their job, such as resetting passwords in the ticketing portal, while all unrelated HR functions like viewing payroll or editing profiles are explicitly denied. By restricting access to only what is required for the task, the organization reduces the attack surface and limits potential damage from compromised credentials or insider misuse. On the Security+ SY0-701 exam, this concept frequently appears in scenario-based questions where you must identify the principle behind role-based access restrictions; a common trap is confusing least privilege with need-to-know, which focuses on data confidentiality rather than system permissions. Remember the mnemonic “Just Enough, Not Everything” to recall that least privilege is about granting the bare minimum access for a role to function.
⚠ Common exam trap
A common mix-up: candidates confuse 'least privilege' with 'separation of duties' because both involve restricting access, but separation of duties specifically requires dividing a single sensitive process among multiple people, whereas least privilege simply limits the scope of permissions for any one person or process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
The help desk analyst is granted only the permissions necessary to perform their job function—resetting passwords—while all other HR functions are explicitly denied. This is the core definition of least privilege: each user or system component receives the minimum set of access rights needed to complete their tasks. By restricting the analyst’s account to password reset operations only, the organization reduces the attack surface and limits potential damage from compromised credentials or insider misuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Least privilege
Why this is correct
Least privilege grants users only the access needed for their duties, so the analyst resets passwords without viewing payroll records, editing profiles, or reaching other HR functions. This directly satisfies the stem's constraint of restricting permissions beyond the ticketing portal's password-reset capability.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers independent controls so a single failure does not grant access; here only one control, role-based permissions, restricts the analyst. It tempts because the analyst's limited access looks like layered restriction, but defense in depth would be correct if multiple overlapping controls each blocked payroll access.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits a single sensitive task across multiple people to prevent fraud; the analyst simply holds a narrow role, with no task divided between parties. It tempts because both concepts limit what one person can do, but separation of duties would be correct if, say, one person created accounts and another approved them.
- ✗
Zero trust
Why it's wrong here
Zero trust continuously verifies every request regardless of network location, using identity, device and context signals; the stem describes static role permissions, not per-request verification. It tempts because least privilege is a zero trust pillar, but zero trust would be correct where access decisions are re-evaluated dynamically on each session.
Go deeper
Related to this question
Learn chapter
Access Control Models (DAC, MAC, RBAC)
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst at a hospital is reviewing user permissions in the electronic health record (EHR) system. The analyst discovers that all nursing staff accounts are members of the 'Administrators' group, which grants full read and write access to all patient records, as well as the ability to modify system configuration settings. The nursing staff's job responsibilities only require viewing and updating records for patients currently assigned to them. Which security principle is most directly violated by this configuration?
medium- A.Defense in depth
- ✓ B.Least privilege
- C.Non-repudiation
- D.Availability
Why B: The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. In this case, nursing staff only need read and write access to records of currently assigned patients, but membership in the 'Administrators' group grants full read/write access to all patient records and the ability to modify system configuration settings, which far exceeds their job requirements. This directly violates least privilege by providing excessive, unnecessary privileges that increase the risk of unauthorized access or accidental misconfiguration.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.