Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?

⚠ Common exam trap

The trap is conflating least privilege with separation of duties; both involve splitting access, but least privilege is about minimizing rights for a task, while separation of duties is about distributing critical functions across people.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

Using a separate non-privileged account for daily tasks like email and web browsing while reserving the admin account for administrative work is a direct application of least privilege. Least privilege means users should have only the minimum access necessary for their current task, and separating admin from daily use reduces the attack surface of privileged credentials. This practice limits exposure of administrative rights to routine activities that could be compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties divides a single task among multiple people to prevent fraud; here one admin simply uses two accounts, which is privilege separation. It is tempting because both concepts split responsibilities, and separation of duties would be correct where no single person should complete a sensitive transaction alone.

  • ✗

    Need-to-know

    Why it's wrong here

    Need-to-know governs access to specific information, not whether an account carries administrative rights; the policy addresses privilege level, not data relevance. It is tempting because both limit access, and need-to-know would be correct where staff only view data required for their particular role.

  • ✓

    Least privilege

    Why this is correct

    Least privilege means granting only the access needed for a task, so routine email and browsing run without administrative rights. Separating the privileged account limits exposure: compromise of the daily-use account cannot yield administrative control over the system.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple independent controls; a single policy of separate accounts is one control, not layered protection. It is tempting because the practice does reduce risk, and defense in depth would be correct where several distinct controls, such as firewalls, patching and monitoring, combine to protect an asset.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.