Courseiva
mediumMultiple Select

ISC2 CC Practice Question: Is implementing a new access control system based…

An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)

⚠ Common exam trap

ISC2 often tests that candidates confuse the principle of least privilege with account management practices like enabling/disabling accounts, or mistakenly think starting with full access and restricting later is acceptable, when in fact least privilege requires a default-deny posture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review permissions regularly

Option A, reviewing permissions regularly, is essential because least privilege requires ongoing verification that users retain only the access needed for their current duties; permissions accumulate over time through role changes and project work, so periodic access reviews (recertification) detect and remove excessive rights. Option B, using role-based access control (RBAC), is essential because assigning permissions to roles rather than individuals lets the organization grant the minimum set of rights required for each job function, and users inherit only those rights through their assigned roles. Option C is wrong because granting default full access and restricting later is the opposite of least privilege, which starts from no access and adds only what is needed. Option D is wrong because enabling accounts after use is nonsensical and would not limit access during active use. Option E is wrong because providing write access to all users violates least privilege by granting broad modification rights regardless of need.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Review permissions regularly

    Why this is correct

    Regular permission reviews detect and remove accumulated entitlements that no longer match a user's current duties. Least privilege decays as roles change, so periodic review is the control that keeps granted access aligned with actual need rather than historical assignment.

  • ✓

    Use role-based access control

    Why this is correct

    Role-based access control assigns permissions to roles rather than individuals, so users receive only the entitlements their job function requires. This structural grouping prevents ad-hoc over-provisioning and makes least privilege enforceable and auditable at scale.

  • ✗

    Grant users default full access and restrict later

    Why it's wrong here

    Least privilege starts from no access and grants only what each role requires; default full access violates this by exposing everything until someone remembers to restrict it. Default full access suits small trusted environments where granular role design is impractical, not least-privilege implementations.

  • ✗

    Enable accounts after use

    Why it's wrong here

    Least privilege requires disabling or removing accounts when no longer needed; enabling accounts after use leaves dormant credentials active and expands the attack surface. Enabling accounts is appropriate during controlled onboarding or reactivation, not as a standing practice.

  • ✗

    Provide write access to all users

    Why it's wrong here

    Granting write access to all users directly contradicts least privilege, which requires each identity to hold only the permissions its role demands. It is tempting because broad write access removes permission-related support tickets, and would suit a small trusted team where every member genuinely edits all data.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.