Courseiva

GSEC Access Control and Password Management Practice Question

Which of the following describes the 'Principle of Least Privilege' in an access control context?

⚠ Common exam trap

Candidates often confuse the Principle of Least Privilege with 'Need to Know' or general access control policies, failing to recognize that PoLP specifically mandates the minimum permissions required for task completion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Providing users only the access required to complete their tasks

The Principle of Least Privilege (PoLP) mandates that users should only be granted the minimum level of access necessary to perform their job functions. This minimizes the attack surface; if a user account is compromised, the potential damage is restricted to the limited permissions assigned to that account. This is a fundamental security concept for preventing lateral movement and privilege escalation during an active incident or breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Granting all employees access to the root directory for troubleshooting

    Why it's wrong here

    Granting root access to all employees is the antithesis of the Principle of Least Privilege. It creates a massive security risk, as any single compromised account could lead to full system destruction or data exfiltration. Troubleshooting should be handled through specific, limited-scope administrative accounts, not by universal access permissions.

  • ✓

    Providing users only the access required to complete their tasks

    Why this is correct

    This definition aligns perfectly with the Principle of Least Privilege. By restricting access to only what is strictly necessary, an organization significantly reduces the impact of accidental mistakes, insider threats, and external attacks, as an attacker will find themselves limited by the restricted permissions of the compromised account.

  • ✗

    Using the same shared password for all administrative accounts

    Why it's wrong here

    Using shared passwords is a dangerous practice that lacks accountability and violates security best practices. It makes it impossible to audit which individual performed a specific action and ensures that if the shared password is leaked, all administrative accounts are immediately compromised, regardless of how many users have access.

  • ✗

    Ensuring all users have administrator rights for software updates

    Why it's wrong here

    Requiring administrator rights for software updates is unnecessary for standard users and increases security risk. Proper configuration management should allow for automated updates or managed deployment tools that do not require giving end-users full administrative control over their local machines, thereby adhering to the principle of least privilege.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.