Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A system administrator notices that a user has…

A system administrator notices that a user has been granted read and write permissions to a folder but should only have read access. Which type of access control issue does this represent?

⚠ Common exam trap

ISC2 often tests the distinction between authorization creep (gradual accumulation over time) and excessive permissions (a one-time over-provisioning), so candidates may confuse the two when the scenario describes a single incorrect assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Excessive permissions

Excessive permissions occur when a user or group is granted more privileges than necessary for their role. In this scenario, the user has read and write access to a folder but should only have read access, meaning the write permission is unnecessary and violates the principle of least privilege. This is a classic example of excessive permissions, as the user has been over-provisioned beyond their job requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Excessive permissions

    Why this is correct

    Granting read and write when only read is required exceeds the user's legitimate need, breaching least privilege. This is excessive permissions: the access control issue is that rights granted are broader than the role demands, not a misconfigured or missing permission.

  • ✗

    Segregation of duties conflict

    Why it's wrong here

    Segregation of duties concerns one person holding conflicting duties that enable fraud, typically across separate business functions. A single user having write where only read is needed is an excess-permission problem, not a conflict between incompatible responsibilities.

  • ✗

    Authorization creep

    Why it's wrong here

    Authorization creep describes permissions gradually accumulating over time through role changes. This user was granted read and write in one assignment, exceeding the read-only requirement immediately, so the fault is excessive privilege at provisioning rather than incremental drift across multiple grants.

  • ✗

    Incomplete revocation

    Why it's wrong here

    Incomplete revocation means rights linger after removal, but here write access was never legitimately held and never withdrawn. The issue is excess privilege granted beyond the read-only requirement — the principle of least privilege breached at assignment, not a failure to revoke existing entitlements.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.