Courseiva
Access Controls Concepts →hardMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?

⚠ Common exam trap

The trap here is focusing on the password strength of the shared account, when the real defect is that one credential destroys individual attribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lack of accountability because shared credentials prevent tracing actions to an individual

Accountability depends on unique identities so that logs can tie each action to one person. Sharing a single privileged credential collapses multiple engineers into one identity, making attribution impossible and undermining nonrepudiation. The remedy is individual named accounts with privileged access management, not merely stronger authentication or additional approvals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Excessive privilege because engineers can manage production databases

    Why it's wrong here

    Administrators may legitimately need privileged database rights to do their jobs, so the mere presence of elevated access is not the defect. The audit finding is about the inability to trace who performed an action, which persists even if the privilege level is appropriate, making excessive privilege the wrong characterization.

  • ✓

    Lack of accountability because shared credentials prevent tracing actions to an individual

    Why this is correct

    Accountability requires that every action can be attributed to a specific identity through unique credentials and audit logs. When several engineers share one privileged account, the logs record only the shared identity, so no one can be held responsible for a given change, which is exactly the control failure the audit identified.

  • ✗

    Missing authorization because the account was never formally approved

    Why it's wrong here

    Authorization concerns whether a subject is permitted to perform an action, and the engineers are in fact permitted to manage the databases. The deficiency lies in attributing actions to individuals rather than in the permission decision itself, so describing the issue as missing authorization misplaces the control failure.

  • ✗

    Weak authentication because the shared account uses only a single password

    Why it's wrong here

    The problem is not the strength or number of authentication factors but the fact that one credential represents many people. Adding a second factor to the shared account would harden login yet still leave every change attributed to the same identity, so authentication strength is not the core weakness here.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.