mediumMultiple Select
ISC2 CC Practice Question: Is implementing a new access control system based…
An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)
⚠ Common exam trap
ISC2 often tests that candidates confuse the principle of least privilege with account management practices like enabling/disabling accounts, or mistakenly think starting with full access and restricting later is acceptable, when in fact least privilege requires a default-deny posture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review permissions regularly
Option A, reviewing permissions regularly, is essential because least privilege requires ongoing verification that users retain only the access needed for their current duties; permissions accumulate over time through role changes and project work, so periodic access reviews (recertification) detect and remove excessive rights. Option B, using role-based access control (RBAC), is essential because assigning permissions to roles rather than individuals lets the organization grant the minimum set of rights required for each job function, and users inherit only those rights through their assigned roles. Option C is wrong because granting default full access and restricting later is the opposite of least privilege, which starts from no access and adds only what is needed. Option D is wrong because enabling accounts after use is nonsensical and would not limit access during active use. Option E is wrong because providing write access to all users violates least privilege by granting broad modification rights regardless of need.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Review permissions regularly
Why this is correct
Regular permission reviews detect and remove accumulated entitlements that no longer match a user's current duties. Least privilege decays as roles change, so periodic review is the control that keeps granted access aligned with actual need rather than historical assignment.
- ✓
Use role-based access control
Why this is correct
Role-based access control assigns permissions to roles rather than individuals, so users receive only the entitlements their job function requires. This structural grouping prevents ad-hoc over-provisioning and makes least privilege enforceable and auditable at scale.
- ✗
Grant users default full access and restrict later
Why it's wrong here
Least privilege starts from no access and grants only what each role requires; default full access violates this by exposing everything until someone remembers to restrict it. Default full access suits small trusted environments where granular role design is impractical, not least-privilege implementations.
- ✗
Enable accounts after use
Why it's wrong here
Least privilege requires disabling or removing accounts when no longer needed; enabling accounts after use leaves dormant credentials active and expands the attack surface. Enabling accounts is appropriate during controlled onboarding or reactivation, not as a standing practice.
- ✗
Provide write access to all users
Why it's wrong here
Granting write access to all users directly contradicts least privilege, which requires each identity to hold only the permissions its role demands. It is tempting because broad write access removes permission-related support tickets, and would suit a small trusted team where every member genuinely edits all data.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.