GCIH Securing Credentials and Data in Cloud Practice Question
Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?
⚠ Common exam trap
Candidates sometimes confuse the principle of least privilege with separation of duties or defense-in-depth when evaluating over-assigned administrative access policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Principle of Least Privilege.
The 'AdministratorAccess' policy provides full, unrestricted access to all services. Assigning this to daily tasks violates the Principle of Least Privilege, which dictates that users should only have the minimum permissions necessary to perform their jobs. Over-privileged accounts are a significant liability, as they allow an attacker who compromises the account to perform any action, including deleting logs or resources, which massively increases the potential impact of an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of Duties.
Why it's wrong here
Separation of duties involves splitting responsibilities between multiple people to prevent fraud. While using an admin account for everything is bad, the specific violation of giving one person too much power is more precisely described as a failure of the principle of least privilege, rather than a lack of segregation.
- ✓
Principle of Least Privilege.
Why this is correct
The Principle of Least Privilege requires that users be granted only the minimum permissions needed to complete a task. 'AdministratorAccess' provides broad, excessive permissions that are rarely required for daily operational tasks. Using such an account for routine work exposes the organization to unnecessary risk if the account is compromised.
- ✗
Defense in Depth.
Why it's wrong here
Defense in Depth refers to layering multiple security controls to protect assets. While having an admin account is a single point of failure, the core issue is the scope of permissions rather than the number of layers. The principle of least privilege is the more direct violation in this scenario.
- ✗
Security through Obscurity.
Why it's wrong here
Security through obscurity relies on hiding information to provide security. This is not a recommended practice and is not the principle being violated here. The use of over-privileged accounts is a fundamental failure of identity and access management policy, which has nothing to do with hiding system implementation details.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.