Courseiva

Need-to-Know Principle Example: Restricting Data Visibility

A finance manager can view only the reports needed for monthly budgeting and cannot see payroll details. Which principle is being applied?

Quick Answer

The answer is need-to-know, because access is limited strictly to the information required for the job. This principle of restricting data visibility ensures that users can only see the specific data necessary to perform their duties, as demonstrated when a finance manager views only monthly budgeting reports while being blocked from payroll details. On the Security+ SY0-701 exam, this concept tests your understanding of access control models like RBAC and ACLs, often appearing in scenario-based questions where a trap answer is “least privilege”—remember, least privilege limits permissions broadly, while need-to-know limits data visibility specifically. A common memory tip is to think “need-to-know = need-to-see,” focusing on what data a role requires rather than what actions they can take.

⚠ Common exam trap

A common mix-up: candidates confuse need-to-know with least privilege, as both limit access, but need-to-know specifically restricts data visibility rather than system permissions or actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Need-to-know, because access is limited to information required for the job.

The principle of need-to-know restricts access to only the information necessary for an individual to perform their job duties. In this scenario, the finance manager can view only monthly budgeting reports and is explicitly blocked from payroll details, which aligns directly with need-to-know. This is typically enforced through access control lists (ACLs) or role-based access control (RBAC) policies that limit data visibility based on job function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Need-to-know, because access is limited to information required for the job.

    Why this is correct

    Need-to-know restricts access to data strictly required for a role's duties, so the finance manager sees budgeting reports but not payroll. This satisfies the stem's constraint that access is limited to information required for the job, distinct from least privilege, which governs permission levels rather than data relevance.

  • ✗

    Zero trust, because the manager uses a password to sign in.

    Why it's wrong here

    Zero trust verifies every request through identity, device and context signals rather than trusting network location; a password alone is not that model. It is tempting because authentication features in zero trust, but the scenario shows least privilege limiting the manager to budgeting reports only.

  • ✗

    Separation of duties, because the manager is part of finance.

    Why it's wrong here

    Separation of duties splits a sensitive task across multiple people to prevent fraud, so it does not describe restricting one user's read access. It is tempting because the manager works in finance, but least privilege is the principle limiting visibility to only the budgeting reports required.

  • ✗

    Defense in depth, because only one report system is being used.

    Why it's wrong here

    Defence in depth layers multiple independent controls; a single report system with restricted views is not that layering. It is tempting because layered controls do harden access, but this scenario demonstrates least privilege, granting the manager only the budgeting reports needed and hiding payroll.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each security principle to the best description.

easy
  • ✓ A.Confidentiality: Restricts access to authorized users.
  • ✓ B.Integrity: Prevents unauthorized modification of data.
  • ✓ C.Availability: Ensures systems are accessible when needed.
  • D.Non-repudiation: Ensures data is unchanged.
  • E.Authentication: Grants permissions.
  • F.Authorization: Verifies identity.

Why A: These pairings match the CIA triad plus additional principles: confidentiality restricts access, integrity prevents unauthorized changes, availability ensures uptime, non-repudiation provides proof of actions, authentication verifies identity, and authorization defines permissions.

Variation 2. Match each security principle to the best workplace example.

easy
  • ✓ A.Least privilege: A user is given access only to files needed for their job.
  • ✓ B.Separation of duties: Two employees must approve a payment to prevent fraud.
  • ✓ C.Defense in depth: A network uses firewalls, IDS, and encryption.
  • ✓ D.Fail safe: A door automatically locks when power fails.
  • E.Least privilege: Two employees must approve a payment.
  • F.Defense in depth: A user is given access only to files needed for their job.

Why A: Each workplace example illustrates a security principle: least privilege grants minimal access, separation of duties divides tasks, defense in depth uses multiple controls, fail safe defaults to safe state, need to know restricts data access, and accountability tracks user actions.

Variation 3. Match each principle to the scenario that best illustrates it.

easy
  • ✓ A.Least privilege: A user is given only the permissions needed to perform their job.
  • ✓ B.Separation of duties: Two people are required to approve a financial transaction.
  • ✓ C.Defense in depth: A network uses firewalls, antivirus, and encryption.
  • D.Least privilege: Two people are required to approve a financial transaction.
  • E.Separation of duties: A user is given only the permissions needed to perform their job.
  • F.Defense in depth: An employee accesses customer data only when required for their role.

Why A: Least privilege limits access rights; separation of duties divides critical tasks; defense in depth uses multiple security layers; need to know restricts data access; accountability tracks actions; fail safe ensures security on failure.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.