Courseiva
hardMultiple Choice

ISC2 CC Practice Question: A security analyst is reviewing logs and finds…

A security analyst is reviewing logs and finds that a user accessed files outside of their department. The user claims it was necessary for a project. Which principle should the analyst use to assess whether this was appropriate?

⚠ Common exam trap

ISC2 often tests the distinction between 'least privilege' (permissions assigned to a role) and 'need to know' (justification for accessing specific data at a specific time), causing candidates to pick 'least privilege' when the scenario involves a user who already has the permission but needs to justify the access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Need to know

The 'need to know' principle restricts access to information based on the specific requirements of a user's role or project. In this scenario, the analyst must verify if the user's project actually required access to those specific files, not just if the user had the technical ability to access them. This principle is a subset of least privilege, focusing on data access rather than system permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Need to know

    Why this is correct

    Need to know limits access to data strictly required for a task, regardless of rank. The analyst must judge whether the project genuinely required those files, so this principle directly tests whether the access was appropriate rather than merely permitted.

  • ✗

    Accountability

    Why it's wrong here

    Accountability establishes that actions are attributable to an identity, but it does not by itself judge whether cross-department access was warranted. Accountability is the right principle when attributing activity, such as confirming which account performed an action.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties prevents one person holding conflicting responsibilities, typically splitting sensitive tasks across roles. It does not assess whether a single user's file access was justified, which is the question here; it applies when designing approval or transaction workflows.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege governs what access a user should hold, but the stem asks which principle evaluates whether an action taken was justified and traceable. Least privilege is the correct lens when designing or reviewing role permissions and entitlements.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.