Courseiva
Question 293 of 1,013
General Security ConceptseasyMatchingObjective-mapped

SY0-701 General Security Concepts Practice Question

Match each security principle to the best workplace example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

A help desk technician can reset passwords but cannot open payroll records.

A customer portal uses MFA, endpoint protection, and network filtering together.

The system rechecks trust before each sensitive action, even from a managed device.

One employee creates a payment batch and a different employee approves it.

An analyst sees only the case files assigned to that investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Least privilege: A user is given access only to files needed for their job.

Each workplace example illustrates a security principle: least privilege grants minimal access, separation of duties divides tasks, defense in depth uses multiple controls, fail safe defaults to safe state, need to know restricts data access, and accountability tracks user actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Least privilege: A user is given access only to files needed for their job.

    Why this is correct

    Least privilege dictates that a user should be granted only the permissions required to perform their specific job functions, nothing more. In this example, restricting access to only necessary files reduces the attack surface and limits the potential damage from a compromised account or malicious insider. This principle is foundational to access control models like RBAC, where roles are mapped to minimal privileges.

  • Separation of duties: Two employees must approve a payment to prevent fraud.

    Why this is correct

    Separation of duties is an anti-fraud and anti-error control that divides a critical process into steps, with different individuals responsible for each step. Requiring two employees to approve a payment ensures that no single person can initiate and authorize a transaction without oversight, forcing collusion for fraud. This principle creates a system of checks and balances within financial workflows and other high-risk operations.

  • Defense in depth: A network uses firewalls, IDS, and encryption.

    Why this is correct

    Defense in depth is a security strategy that layers heterogeneous controls — such as perimeter firewalls, network intrusion detection systems, and encryption — so that if one layer is bypassed, others still protect the asset. This avoids reliance on any single point of failure and addresses threats at multiple phases of the attack chain. The example illustrates the use of both preventive, detective, and data protection mechanisms.

  • Fail safe: A door automatically locks when power fails.

    Why this is correct

    Fail safe means that when a system or component fails, it automatically reverts to the most secure default state, rather than an open or permissive state. In this example, the door locks on power loss, preventing unauthorized entry even if the access control system is unavailable. This is distinct from fail-open, which would unlock and potentially compromise security, and it is a common requirement for physical security and emergency-mode system behavior.

  • Least privilege: Two employees must approve a payment.

    Why it's wrong here

    This is not least privilege — it is separation of duties. Least privilege governs the scope of permissions a single user holds, minimizing access to job-relevant resources. Requiring two approvals for a payment is a task-level control that prevents unilateral action and fraud by dividing authority, not by limiting file or system access.

  • Defense in depth: A user is given access only to files needed for their job.

    Why it's wrong here

    This is not defense in depth — it is least privilege, because it restricts a user's file access to only what is necessary for their job. Defense in depth is about layering multiple security controls across the environment (e.g., firewalls, IDS, encryption) to provide redundancy. Confusing these principles blurs the distinction between access control minimization and layered network defense.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: May 2, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.