ISC2 CC Access Controls Concepts Practice Question
A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?
⚠ Common exam trap
The trap is conflating least privilege with separation of duties; both involve splitting access, but least privilege is about minimizing rights for a task, while separation of duties is about distributing critical functions across people.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Using a separate non-privileged account for daily tasks like email and web browsing while reserving the admin account for administrative work is a direct application of least privilege. Least privilege means users should have only the minimum access necessary for their current task, and separating admin from daily use reduces the attack surface of privileged credentials. This practice limits exposure of administrative rights to routine activities that could be compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of duties
Why it's wrong here
Separation of duties divides a single task among multiple people to prevent fraud; here one admin simply uses two accounts, which is privilege separation. It is tempting because both concepts split responsibilities, and separation of duties would be correct where no single person should complete a sensitive transaction alone.
- ✗
Need-to-know
Why it's wrong here
Need-to-know governs access to specific information, not whether an account carries administrative rights; the policy addresses privilege level, not data relevance. It is tempting because both limit access, and need-to-know would be correct where staff only view data required for their particular role.
- ✓
Least privilege
Why this is correct
Least privilege means granting only the access needed for a task, so routine email and browsing run without administrative rights. Separating the privileged account limits exposure: compromise of the daily-use account cannot yield administrative control over the system.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls; a single policy of separate accounts is one control, not layered protection. It is tempting because the practice does reduce risk, and defense in depth would be correct where several distinct controls, such as firewalls, patching and monitoring, combine to protect an asset.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Exposure
Exposure is the measure of potential loss or harm to an organization's assets when a vulnerability is exploited by a threat, often expressed as the window of time or degree of access an attacker has.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.