ISC2 CC Security Principles Practice Question
A security analyst is reviewing access control models. Which two of the following are characteristics of the principle of least privilege? (Choose two.)
⚠ Common exam trap
The trap here is equating role-based access control with least privilege, when RBAC is merely a tool that can help implement least privilege but does not guarantee it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Users are granted only the minimum access rights necessary to perform their job functions.
The correct answers are granting only minimum necessary access and limiting access duration to when needed. These directly reflect the principle of least privilege, which aims to restrict user rights to the bare minimum required for their duties and only for as long as necessary. Role-based access, default read-only access, and permanent admin rights do not embody least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Administrative privileges are permanently assigned to senior management.
Why it's wrong here
Permanently assigning administrative privileges to senior management violates least privilege, as they may not need those rights for their daily tasks. Least privilege advocates for temporary, need-based elevation, not permanent assignment. This option describes a common but insecure practice, so it is not a correct characteristic.
- ✓
Users are granted only the minimum access rights necessary to perform their job functions.
Why this is correct
Least privilege dictates that users should have only the permissions required to complete their tasks, no more. This minimizes the attack surface and reduces the potential damage from accidental or malicious actions. Granting minimum access is the core definition of least privilege, making this a correct characteristic.
- ✗
All users are granted read-only access to all resources by default.
Why it's wrong here
Granting read-only access to all resources is not least privilege; it may still violate the principle if users do not need that access. Least privilege requires that access be restricted to only what is necessary, not a blanket read-only policy. This option is too broad and could grant unnecessary access, so it is incorrect.
- ✓
Users are given access only for the duration needed to complete a specific task.
Why this is correct
This describes just-in-time (JIT) access or temporary elevation, which is a practical implementation of least privilege. By granting access only when needed and for a limited time, the principle of least privilege is enforced. This is a correct characteristic because it ensures users do not retain unnecessary permissions beyond the task duration.
- ✗
Access rights are based on the user's role within the organization.
Why it's wrong here
Basing access on roles is role-based access control (RBAC), which can implement least privilege but is not a defining characteristic of least privilege itself. Least privilege is about the amount of access, not the method of assignment. RBAC can grant excessive rights if roles are not carefully designed, so this is not a correct characteristic.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.