easyMultiple Choice
ISC2 CC Practice Question: A system administrator is configuring permissions…
A system administrator is configuring permissions for a new file server. To adhere to the principle of least privilege, which approach should the administrator take?
⚠ Common exam trap
Watch out — candidates often confuse 'department membership' with 'job duties' — department-based access sounds reasonable but is broader than least privilege requires, and candidates often pick it as a middle-ground answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant each user only the permissions necessary to perform their job duties.
The principle of least privilege means granting each user only the minimum permissions required to perform their job functions — nothing more. Option C directly embodies this by tying permissions to actual job duties rather than broad group membership or department-wide access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant permissions only to the IT department.
Why it's wrong here
Restricting permissions to the IT department excludes the business users who own and need the data, so the server becomes unusable for its actual purpose. It is tempting because administrators hold broad rights, and would fit a dedicated management or backup share used solely by IT staff.
- ✗
Grant permissions based on the user's department membership.
Why it's wrong here
Department membership is a broad role attribute, so it grants access to every file the department touches rather than only the resources a given user needs. It is tempting because role-based groups scale well, and would be correct where job function genuinely matches required access.
- ✓
Grant each user only the permissions necessary to perform their job duties.
Why this is correct
Granting each user only the permissions their job duties require directly implements least privilege, which demands minimal necessary access. This satisfies the stem's constraint by restricting rights to job scope rather than broad defaults, reducing the attack surface and limiting potential damage from compromised accounts or accidental misuse.
- ✗
Grant all users full control to simplify management.
Why it's wrong here
Granting full control to everyone directly violates least privilege by giving every account write and delete rights on all data. It is tempting because it removes permission-related support tickets, and would only suit a lab or isolated share where no data sensitivity or accountability exists.
Go deeper
Related to this question
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.