Courseiva
Security Principles →hardMultiple Select

ISC2 CC Security Principles Practice Question

A security analyst is reviewing access control models. Which two of the following are characteristics of the principle of least privilege? (Choose two.)

⚠ Common exam trap

The trap here is equating role-based access control with least privilege, when RBAC is merely a tool that can help implement least privilege but does not guarantee it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Users are granted only the minimum access rights necessary to perform their job functions.

The correct answers are granting only minimum necessary access and limiting access duration to when needed. These directly reflect the principle of least privilege, which aims to restrict user rights to the bare minimum required for their duties and only for as long as necessary. Role-based access, default read-only access, and permanent admin rights do not embody least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Administrative privileges are permanently assigned to senior management.

    Why it's wrong here

    Permanently assigning administrative privileges to senior management violates least privilege, as they may not need those rights for their daily tasks. Least privilege advocates for temporary, need-based elevation, not permanent assignment. This option describes a common but insecure practice, so it is not a correct characteristic.

  • ✓

    Users are granted only the minimum access rights necessary to perform their job functions.

    Why this is correct

    Least privilege dictates that users should have only the permissions required to complete their tasks, no more. This minimizes the attack surface and reduces the potential damage from accidental or malicious actions. Granting minimum access is the core definition of least privilege, making this a correct characteristic.

  • ✗

    All users are granted read-only access to all resources by default.

    Why it's wrong here

    Granting read-only access to all resources is not least privilege; it may still violate the principle if users do not need that access. Least privilege requires that access be restricted to only what is necessary, not a blanket read-only policy. This option is too broad and could grant unnecessary access, so it is incorrect.

  • ✓

    Users are given access only for the duration needed to complete a specific task.

    Why this is correct

    This describes just-in-time (JIT) access or temporary elevation, which is a practical implementation of least privilege. By granting access only when needed and for a limited time, the principle of least privilege is enforced. This is a correct characteristic because it ensures users do not retain unnecessary permissions beyond the task duration.

  • ✗

    Access rights are based on the user's role within the organization.

    Why it's wrong here

    Basing access on roles is role-based access control (RBAC), which can implement least privilege but is not a defining characteristic of least privilege itself. Least privilege is about the amount of access, not the method of assignment. RBAC can grant excessive rights if roles are not carefully designed, so this is not a correct characteristic.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.