ISC2 CC Access Controls Concepts Practice Question
A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?
⚠ Common exam trap
The trap here is focusing on the password strength of the shared account, when the real defect is that one credential destroys individual attribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lack of accountability because shared credentials prevent tracing actions to an individual
Accountability depends on unique identities so that logs can tie each action to one person. Sharing a single privileged credential collapses multiple engineers into one identity, making attribution impossible and undermining nonrepudiation. The remedy is individual named accounts with privileged access management, not merely stronger authentication or additional approvals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Excessive privilege because engineers can manage production databases
Why it's wrong here
Administrators may legitimately need privileged database rights to do their jobs, so the mere presence of elevated access is not the defect. The audit finding is about the inability to trace who performed an action, which persists even if the privilege level is appropriate, making excessive privilege the wrong characterization.
- ✓
Lack of accountability because shared credentials prevent tracing actions to an individual
Why this is correct
Accountability requires that every action can be attributed to a specific identity through unique credentials and audit logs. When several engineers share one privileged account, the logs record only the shared identity, so no one can be held responsible for a given change, which is exactly the control failure the audit identified.
- ✗
Missing authorization because the account was never formally approved
Why it's wrong here
Authorization concerns whether a subject is permitted to perform an action, and the engineers are in fact permitted to manage the databases. The deficiency lies in attributing actions to individuals rather than in the permission decision itself, so describing the issue as missing authorization misplaces the control failure.
- ✗
Weak authentication because the shared account uses only a single password
Why it's wrong here
The problem is not the strength or number of authentication factors but the fact that one credential represents many people. Adding a second factor to the shared account would harden login yet still leave every change attributed to the same identity, so authentication strength is not the core weakness here.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Accountability
Accountability is the security principle that ensures actions and identity are linked so that a person or system can be held responsible for their activities.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.