Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A company implements role-based access control…

A company implements role-based access control (RBAC) to ensure users have only the permissions necessary for their job roles. This is an example of:

⚠ Common exam trap

CC often tests the confusion between least privilege (minimum permissions) and need-to-know (minimum information), which sound similar but apply to different domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

RBAC grants users only the permissions required for their job roles, which is the definition of least privilege — the principle that subjects should have the minimum access necessary to perform their function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Least privilege

    Why this is correct

    RBAC enforces least privilege by granting only the permissions each job role requires, directly satisfying the stem's constraint that users hold solely the access necessary for their duties. Unlike broader models such as discretionary access control, it scopes entitlements to role definitions rather than individual discretion, minimising standing privileges.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple independent controls so one failure does not expose the system; RBAC alone assigns permissions by job role. It is tempting because RBAC often forms one layer within a defence-in-depth strategy, but the stem describes permission scoping, not layered controls.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a critical task across multiple people so no single user completes it alone; RBAC restricts each role's permissions instead. It is tempting because both are access-control principles, and separation of duties is correct when one person must not both request and approve an action.

  • ✗

    Need-to-know

    Why it's wrong here

    Need-to-know restricts access to specific data based on its sensitivity, whereas RBAC grants permissions according to job role regardless of individual data items. It is tempting because both limit access, and need-to-know is correct when clearance to particular classified information, not role, governs access.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.