Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?

⚠ Common exam trap

The trap here is choosing least privilege because access is limited, when the scenario is specifically about limiting which data records a user can see, which is need to know.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Need to know

Need to know restricts access to only the information a user requires for their job, which is why the teller sees only their branch's customers. Least privilege limits the types of permissions granted, separation of duties splits tasks among users, and defense in depth layers controls. The record-level restriction described maps to need to know.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties divides a sensitive task among multiple people so that no single person can complete it alone, such as requiring two approvals for a funds transfer. The teller's restriction to their branch's customers does not involve splitting a task between users. Nothing in the scenario describes a task being divided, so this principle does not apply.

  • ✓

    Need to know

    Why this is correct

    Need to know limits access to only the specific information a user requires to perform their duties. The teller needs records for their own branch's customers to serve them, but has no legitimate need to view customers at other branches. Restricting the teller's visibility to only the records necessary for their work is the essence of the need-to-know principle.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege means granting only the minimum permissions needed to perform a job, such as giving the teller read and update rights rather than delete rights. The scenario does describe limited permissions, but the specific restriction to their own branch's customers is about which records the teller may see, not about reducing the permission types. This record-level scoping is better explained by another principle.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple independent controls so that the failure of one control does not expose the system, such as combining firewalls, encryption, and monitoring. The scenario describes a single logical restriction on which records the teller can view, not a stack of overlapping controls. Defense in depth addresses redundancy of controls, not the scope of data visibility.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.