hardMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: An organization's security policy requires that…
An organization's security policy requires that all access to sensitive data must be approved by a data owner. An administrator configures a system to enforce this. Which principle is being implemented?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization
Authorization is the process of granting or denying access to resources based on the authenticated user's permissions. In this scenario, the requirement that access must be approved by a data owner before granting access is a classic example of implementing authorization controls. Option A (Accountability) is incorrect because accountability involves tracking user actions and holding users responsible, not requiring approval. Option B (Least privilege) is incorrect because least privilege is about granting the minimum necessary permissions, but it does not require a separate approval step by a data owner. Option C (Non-repudiation) is incorrect because non-repudiation ensures that a party cannot deny having performed an action, typically through digital signatures or logs, not through access approvals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accountability
Why it's wrong here
Accountability tracks actions, but does not define the approval process for access.
- ✗
Least privilege
Why it's wrong here
Least privilege limits access to the minimum necessary, but does not mandate a separate approver like a data owner.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation prevents denial of actions, not access control.
- ✓
Authorization
Why this is correct
Authorization determines what actions an authenticated user is permitted to perform, based on approval from the data owner.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Accountability
Accountability is the security principle that ensures actions and identity are linked so that a person or system can be held responsible for their activities.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 976 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.