Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?

⚠ Common exam trap

Candidates sometimes confuse the principle of least privilege with separation of duties or defense-in-depth when evaluating over-assigned administrative access policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Principle of Least Privilege.

The 'AdministratorAccess' policy provides full, unrestricted access to all services. Assigning this to daily tasks violates the Principle of Least Privilege, which dictates that users should only have the minimum permissions necessary to perform their jobs. Over-privileged accounts are a significant liability, as they allow an attacker who compromises the account to perform any action, including deleting logs or resources, which massively increases the potential impact of an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of Duties.

    Why it's wrong here

    Separation of duties involves splitting responsibilities between multiple people to prevent fraud. While using an admin account for everything is bad, the specific violation of giving one person too much power is more precisely described as a failure of the principle of least privilege, rather than a lack of segregation.

  • ✓

    Principle of Least Privilege.

    Why this is correct

    The Principle of Least Privilege requires that users be granted only the minimum permissions needed to complete a task. 'AdministratorAccess' provides broad, excessive permissions that are rarely required for daily operational tasks. Using such an account for routine work exposes the organization to unnecessary risk if the account is compromised.

  • ✗

    Defense in Depth.

    Why it's wrong here

    Defense in Depth refers to layering multiple security controls to protect assets. While having an admin account is a single point of failure, the core issue is the scope of permissions rather than the number of layers. The principle of least privilege is the more direct violation in this scenario.

  • ✗

    Security through Obscurity.

    Why it's wrong here

    Security through obscurity relies on hiding information to provide security. This is not a recommended practice and is not the principle being violated here. The use of over-privileged accounts is a fundamental failure of identity and access management policy, which has nothing to do with hiding system implementation details.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.