Courseiva
Access Controls Concepts →mediumMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?

⚠ Common exam trap

It's easy for candidates to confuse least privilege with other access control principles like separation of duties or defense in depth, especially when the policy mentions 'minimum permissions' which directly points to least privilege, but candidates might overlook need-to-know as a complementary principle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Need-to-know

Option E, least privilege, is correct because the policy explicitly states that employees should be granted only the minimum permissions required to perform their job functions, which is the exact definition of the least privilege principle. Option D, need-to-know, is correct because it restricts access to information and resources only to those who require them for their job duties, complementing least privilege by limiting data exposure. Together, these principles reduce the attack surface and potential impact if an account is compromised. Option A, defense in depth, is not correct because it refers to layering multiple security controls rather than limiting permissions. Option B, separation of duties, is not correct because it involves dividing tasks among different individuals to prevent fraud or error, not minimizing permissions. Option C, privileged access management, is not correct because it focuses on managing and monitoring elevated accounts, not on the general principle of minimum permissions for all employees.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth is a layered security strategy using multiple independent controls (e.g., firewalls, antivirus, encryption) to protect against a single point of failure. It does not address the principle of granting only the minimum permissions necessary for a role, which is the core requirement of the scenario. This option is tempting because layered defences are a common security best practice, and they would be the correct choice if the question asked about mitigating the impact of a single control being bypassed, rather than about restricting user permissions.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a critical task across multiple people to prevent fraud, which the stem does not describe. It applies when no single person should complete a sensitive transaction alone, such as approving and paying an invoice.

  • ✗

    Privileged access management

    Why it's wrong here

    Privileged access management tools vault, rotate and monitor elevated credentials; it is a control for administering privileged accounts, not the principle of granting minimal permissions. It fits environments needing session recording and just-in-time admin access.

  • ✓

    Need-to-know

    Why this is correct

    Need-to-know restricts access to information strictly required for a specific task, independent of seniority. Combined with least privilege, it satisfies the policy's minimum-permissions requirement by limiting data exposure, reducing impact if the account is compromised.

  • ✓

    Least privilege

    Why this is correct

    Least privilege grants each account only the minimum permissions necessary for its job function, directly matching the policy. This limits the blast radius of a compromised account, since the attacker inherits only those restricted rights rather than broader access.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.