Courseiva

CCNA Access Controls Concepts Questions

71 of 146 questions · Page 2/2 · Access Controls Concepts · Answers revealed

76
Multi-Selectmedium

A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)

Select 2 answers
A.Fencing around the building
B.Complex password policy
C.Cable locks on individual servers
D.Session timeout settings
E.Biometric reader on server room door
AnswersA, E

Perimeter fencing establishes the outermost physical boundary, deterring and delaying intruders before they reach the building housing the server room. It forms the first layer of a defence-in-depth strategy, complementing interior controls such as locks and cameras.

Why this answer

Fencing around the building (A) is a valid physical security layer because it establishes the outermost perimeter control, deterring and delaying unauthorized access before an attacker can reach the facility itself. A biometric reader on the server room door (E) is also correct because it enforces an authentication-based access control at the innermost physical layer, ensuring only authorized personnel can enter the room housing the servers. Together these represent defense-in-depth at the perimeter and at the asset boundary.

The remaining options are logical/technical controls rather than physical layers: a complex password policy (B) governs authentication credentials, cable locks on individual servers (C) are a device-level physical tether but not a room/building security layer in this context, and session timeout settings (D) are logical access controls that terminate idle sessions.

Exam trap

The trap here is confusing logical security controls (passwords, session timeouts) with physical security layers, and overlooking that cable locks, while physical, are not a primary layer for server room protection.

77
MCQeasy

Which of the following best describes the purpose of a session timeout?

A.To automatically log out inactive users
B.To enforce password complexity
C.To restrict access based on need-to-know
D.To prevent brute-force attacks
AnswerA

A session timeout is a crucial security mechanism designed to automatically terminate a user's active session after a specified period of inactivity. This process invalidates the session token or cookie, forcing re-authentication and preventing unauthorised access to an unattended workstation or application. Its primary purpose, as the stem asks, is to enhance security by ensuring inactive users are logged out, mitigating risks of session hijacking or data exposure.

Why this answer

A session timeout is a security control that automatically terminates a user's authenticated session after a defined period of inactivity. Its core purpose is to prevent unauthorized access when a user leaves a workstation unattended, reducing the window of opportunity for someone else to use the still-authenticated session. It does not enforce password rules, restrict data by need-to-know, or block brute-force attempts.

Exam trap

The trap here is confusing authentication hardening controls (password complexity, lockout) with session lifecycle controls (timeout), since all are 'security settings' but address different attack windows.

How to eliminate wrong answers

Option B is wrong because password complexity is enforced by password policy settings (length, character classes, history), not by session timeouts. Option C is wrong because need-to-know access restriction is implemented through authorization models such as RBAC, ABAC, or ACLs, not session expiration. Option D is wrong because brute-force protection is handled by account lockout thresholds, rate limiting, CAPTCHAs, or MFA, not by timing out idle sessions.

78
MCQmedium

A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?

A.Accounting
B.Authentication
C.Authorisation
D.Identification
AnswerD

Entering a username asserts a claimed identity to the system, which is the identification phase. Authentication would then verify that claim via the password. The username alone is an identifier, not proof, so it maps to identification within the access control process.

Why this answer

Entering a username is the act of claiming an identity to the system, which is the identification phase. Authentication is the subsequent step where the password is verified to prove that claimed identity.

Exam trap

The trap here is conflating identification with authentication — candidates see 'username and password' and pick authentication, forgetting that the username alone is the identification step.

How to eliminate wrong answers

Option A is wrong because accounting is the logging and tracking of user activity (e.g., audit trails, session records), not the act of presenting an identity. Option B is wrong because authentication is the verification of the credential (the password step), not the username entry itself. Option C is wrong because authorisation determines what resources the authenticated user may access, which occurs after both identification and authentication.

79
MCQhard

A financial services firm must enforce access decisions based on data sensitivity labels assigned by a central authority, and users cannot change these labels or grant access to others. Which access control model is the firm implementing?

A.Attribute-Based Access Control (ABAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerC

MAC uses security labels assigned by a central authority and compares them against user clearances to make access decisions. Users cannot modify labels or pass access to others, which aligns exactly with the scenario. This centralized, non-discretionary enforcement is the hallmark of MAC and satisfies the firm's requirement to control access based on data sensitivity labels.

Why this answer

Mandatory Access Control relies on security labels assigned by a central authority and compares them with user clearances. Users cannot alter labels or delegate access, which matches the firm's requirement to enforce decisions based on data sensitivity. Discretionary Access Control and Role-Based Access Control allow owner or role-based discretion, and Attribute-Based Access Control is broader and policy-driven, so none of them captures the centralized, non-discretionary label enforcement described.

Exam trap

The trap here is confusing label-based access with role-based access, since both can restrict users, but only Mandatory Access Control requires centrally assigned labels that users cannot change.

80
MCQhard

An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Need-to-know
AnswerA

Least privilege grants each account only the permissions its role requires, so a compromised user account exposes a narrow slice of resources rather than the whole environment. Limiting standing access directly caps the blast radius an attacker can reach after credential theft.

Why this answer

Least privilege is the principle of granting users only the minimum access rights necessary to perform their job functions. If an attacker compromises a user's account, the damage is limited because the account has restricted permissions. This directly addresses limiting damage from a compromised account.

Exam trap

CC often tests the application of security principles, and candidates may confuse least privilege with need-to-know or separation of duties, especially when the scenario involves limiting damage from a compromised account.

How to eliminate wrong answers

Option B is wrong because separation of duties divides tasks among multiple users to prevent fraud, but it does not directly limit damage from a single compromised account. Option C is wrong because defense in depth involves multiple layers of security, which can help but is not the most direct principle for limiting damage from a compromised account. Option D is wrong because need-to-know restricts access to information based on job requirements, similar to least privilege but more focused on data access; however, least privilege is broader and more directly applies to limiting account permissions.

81
MCQhard

In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?

A.DC=company, DC=com, OU=Sales, CN=John Smith
B.OU=Sales, CN=John Smith, DC=company, DC=com
C.CN=John Smith, OU=Sales, DC=company, DC=com
D.CN=John Smith, DC=Sales, DC=company, DC=com
AnswerC

CN=John Smith, OU=Sales, DC=company, DC=com satisfies LDAP's leaf-to-root ordering, placing the common name first, then the organizational unit, then each domain component separately. Splitting company.com into two DC attributes matches the stem's domain constraint, unlike a single DC=company.com entry.

Why this answer

An LDAP distinguished name is written from the most specific component (the leaf object) to the least specific (the root of the directory tree), separated by commas. For John Smith in the Sales OU of company.com, the correct order is CN=John Smith, OU=Sales, DC=company, DC=com. The CN identifies the user object, the OU identifies the organizational unit, and the DC components identify the domain.

Exam trap

The trap is ordering — candidates often write DNs top-down like a URL, but LDAP requires leaf-to-root ordering, and mixing up OU and DC attributes compounds the error.

How to eliminate wrong answers

Option A is wrong because it reverses the order, starting with the domain components and ending with the user, which is the opposite of LDAP DN syntax. Option B is wrong because it places OU=Sales before CN=John Smith, violating the leaf-to-root ordering rule. Option D is wrong because it uses DC=Sales instead of OU=Sales; 'Sales' is an organizational unit, not a domain component, so the attribute type is incorrect.

82
MCQmedium

A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?

A.Password complexity
B.Biometric authentication
C.Session timeout
D.Account lockout
AnswerC

Session timeout automatically locks or terminates an idle session after a defined inactivity period, so an unattended workstation cannot be used by an unauthorised person. It directly addresses the walk-away threat rather than authentication or authorisation at logon.

Why this answer

A session timeout automatically locks or logs out a user after a period of inactivity, directly addressing the risk of an unattended workstation being used by an unauthorized person. It is the standard control for this scenario because it terminates the authenticated session without requiring the user to manually log off. Password complexity, biometrics, and account lockout address different threats.

Exam trap

The trap is that multiple options are 'access controls,' so candidates must match the control to the specific threat — unattended workstation — rather than picking a generally strong control like biometrics.

How to eliminate wrong answers

Option A is wrong because password complexity strengthens credentials against guessing and brute force but does nothing to protect an already-authenticated session left open. Option B is wrong because biometric authentication verifies identity at login but does not automatically secure a session after the user walks away. Option D is wrong because account lockout disables an account after repeated failed logins, which mitigates brute-force attacks, not unattended-session abuse.

83
Multi-Selectmedium

A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?

Select 2 answers
A.Defense in depth
B.Separation of duties
C.Privileged access management
D.Need-to-know
E.Least privilege
AnswersD, E

Need-to-know restricts access to information strictly required for a specific task, independent of seniority. Combined with least privilege, it satisfies the policy's minimum-permissions requirement by limiting data exposure, reducing impact if the account is compromised.

Why this answer

Option E, least privilege, is correct because the policy explicitly states that employees should be granted only the minimum permissions required to perform their job functions, which is the exact definition of the least privilege principle. Option D, need-to-know, is correct because it restricts access to information and resources only to those who require them for their job duties, complementing least privilege by limiting data exposure. Together, these principles reduce the attack surface and potential impact if an account is compromised.

Option A, defense in depth, is not correct because it refers to layering multiple security controls rather than limiting permissions. Option B, separation of duties, is not correct because it involves dividing tasks among different individuals to prevent fraud or error, not minimizing permissions. Option C, privileged access management, is not correct because it focuses on managing and monitoring elevated accounts, not on the general principle of minimum permissions for all employees.

Exam trap

The trap here is confusing least privilege with other access control principles like separation of duties or defense in depth, especially when the policy mentions 'minimum permissions' which directly points to least privilege, but candidates might overlook need-to-know as a complementary principle.

84
MCQeasy

A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?

A.Separation of duties
B.Need-to-know
C.Defense in depth
D.Least privilege
AnswerD

Least privilege grants each user only the minimum rights required for their job, exactly matching the stem's constraint. Unlike role-based or mandatory models, it limits permissions to necessity, reducing the attack surface and potential damage from compromised or misused accounts.

Why this answer

Least privilege means granting users only the minimum permissions required to perform their job functions — nothing more. The administrator is explicitly ensuring each user has only the rights needed, which is the textbook definition of least privilege. This principle limits the blast radius of compromised accounts and reduces accidental or malicious misuse of permissions.

Exam trap

The trap here is confusing least privilege with need-to-know — both limit access, but least privilege is about the minimum permissions to do the job, while need-to-know is about access to specific information.

How to eliminate wrong answers

Option A is wrong because separation of duties is about dividing critical tasks among multiple people so no single person can complete a sensitive action alone — it is not about minimizing each user's permission set. Option B is wrong because need-to-know refers specifically to limiting access to information based on whether the user requires it for their role, typically applied to data classification rather than general permission minimization. Option C is wrong because defense in depth is a layered security strategy using multiple overlapping controls, not a principle about individual user rights.

85
MCQmedium

An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?

A.Common Name
B.Domain Component
C.Organizational Unit
D.Country Name
AnswerA

In an LDAP distinguished name, CN stands for Common Name, the leftmost relative distinguished name identifying the entry itself. Here it names the object "John Smith" within the Sales organisational unit, satisfying the stem's requirement to identify what the CN attribute represents in the DN hierarchy.

Why this answer

In an LDAP distinguished name (DN), 'CN' stands for Common Name. It is used to represent the name of an object, such as a user or a group. In the example 'CN=John Smith,OU=Sales,DC=company,DC=com', 'CN=John Smith' indicates the common name of the entry, which is typically the user's full name.

Exam trap

The trap here is confusing the abbreviations of LDAP DN components, especially CN with DC or OU, so candidates must memorize the standard abbreviations.

How to eliminate wrong answers

Option B is wrong because 'DC' stands for Domain Component, not 'CN'. Option C is wrong because 'OU' stands for Organizational Unit, not 'CN'. Option D is wrong because 'C' stands for Country Name, not 'CN'.

86
MCQeasy

A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?

A.Separation of duties
B.Need to know
C.Defense in depth
D.Least privilege
AnswerD

Least privilege grants each user only the access rights necessary for their job, nothing more. This satisfies the stem's requirement by restricting permissions to the minimum needed, reducing the blast radius of compromised accounts or insider misuse.

Why this answer

Least privilege means granting users only the minimum access rights required to perform their job functions, nothing more. This directly matches the scenario where the administrator wants each user to have only the access necessary for their role. It reduces the attack surface and limits potential damage from compromised accounts.

Exam trap

The trap here is confusing least privilege with need to know or separation of duties; candidates often pick need to know because it sounds similar, but least privilege is specifically about minimum access rights for a job role.

How to eliminate wrong answers

Option A is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or errors, rather than limiting each user to the minimum access for their job. Option B is wrong because need to know focuses on restricting access to information based on whether the user requires it for a specific task, which is a subset of least privilege but not the overarching principle described. Option C is wrong because defense in depth is a layered security strategy, not a principle about individual user permissions.

87
MCQmedium

A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?

A.Biometric reader on server room door
B.Cable locks on laptops
C.Visitor badge policy
D.Fencing around the property
AnswerD

Fencing defines the outer physical boundary of a site, delaying or deterring intruders before they reach the building. It therefore operates as an external perimeter measure, satisfying the stem's requirement, whereas locks and badge readers sit at internal entry points.

Why this answer

Fencing around the property is an external perimeter security measure because it establishes the outermost physical boundary of the facility, deterring and delaying unauthorized entry before an attacker reaches the building. Perimeter controls focus on the site's outer edge, while the other options protect interior assets or personnel behavior. Fencing, bollards, lighting, and gates are classic examples of external perimeter defenses.

Exam trap

The trap is that candidates pick the most 'secure-sounding' control (biometrics) rather than the one that actually sits at the external perimeter — the exam tests whether you can distinguish perimeter from interior and administrative controls.

How to eliminate wrong answers

Option A is wrong because a biometric reader on a server room door is an interior access control protecting a specific high-value room, not the external perimeter. Option B is wrong because cable locks on laptops are endpoint-level physical controls that secure individual portable assets, not the facility perimeter. Option C is wrong because a visitor badge policy is an administrative control governing personnel movement inside the facility, not a physical external perimeter measure.

88
MCQmedium

What is the primary purpose of a Privileged Access Management (PAM) solution?

A.To provide single sign-on for all applications
B.To manage visitor access to the building
C.To enforce password complexity for all users
D.To control and monitor privileged access to critical systems
AnswerD

PAM brokers privileged sessions through a controlled vault, enforcing approval workflows, credential checkout and full session recording. This satisfies the scenario's need to both restrict who reaches critical systems and retain auditable evidence of every administrative action performed.

Why this answer

A Privileged Access Management (PAM) solution is specifically designed to secure, control, and monitor the use of privileged accounts—such as root, administrator, or service accounts—that have elevated access to critical systems. It typically provides features like credential vaulting, session recording, just-in-time access, and approval workflows to prevent misuse and detect malicious activity. Unlike general IAM or SSO tools, PAM focuses on the highest-risk accounts and enforces least privilege for administrative actions.

Thus, option D accurately captures its primary purpose.

Exam trap

The trap here is confusing PAM with general IAM or SSO solutions, as candidates may think any access management tool covers privileged access, but PAM specifically targets elevated accounts and their monitoring.

How to eliminate wrong answers

Option A is wrong because single sign-on (SSO) is an authentication convenience provided by Identity and Access Management (IAM) or federated identity solutions, not the core function of PAM; PAM may integrate with SSO but does not primarily provide it. Option B is wrong because managing visitor access to a building is a physical security function, unrelated to logical access controls for IT systems. Option C is wrong because enforcing password complexity for all users is a general password policy typically handled by directory services or IAM, whereas PAM focuses on privileged accounts and often uses vaulting and rotation rather than just complexity rules.

89
MCQeasy

A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?

A.Something you know and something you have
B.Something you know and something you are
C.Something you have and something you are
D.Something you know and somewhere you are
AnswerA

The password represents something the user knows, while the one-time code generated by the mobile authenticator app represents something the user has, namely the registered device. Combining these two distinct factor types satisfies multi-factor authentication. This pairing is the most common MFA implementation and directly matches the scenario's username/password plus app-generated code.

Why this answer

Multi-factor authentication requires combining factors from different categories. The password is a knowledge factor, and the one-time code from a registered mobile app is a possession factor. Together they form something you know plus something you have.

The other pairings involve biometrics or location, neither of which appears in the described login sequence, so they do not accurately describe the factors in use.

Exam trap

The trap here is treating a one-time code as a knowledge factor because the user reads and types it, rather than recognizing it as a possession factor tied to the device.

90
Multi-Selectmedium

A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?

Select 2 answers
A.Fencing around the property
B.Lighting in parking lots
C.Biometric reader on server room door
D.Cable locks on laptops
E.Chassis locks on servers
AnswersA, B

Fencing establishes a physical barrier at the property boundary, delaying or deterring intruders before they reach the building. It satisfies the external perimeter constraint by providing the outermost layer of physical protection, which lighting and interior controls then reinforce.

Why this answer

Fencing around the property (A) is a correct answer because it is a perimeter-layer physical control that establishes a physical boundary and delays or deters intruders before they reach the facility. Lighting in parking lots (B) is also correct because exterior lighting is a classic layered perimeter control that deters intruders, removes concealment, and supports CCTV or guard surveillance. Together, fencing and lighting represent complementary external perimeter defenses that support defense in depth.

The unmarked options do not belong because a biometric reader on a server room door (C) is an interior access control for a specific high-security room, not an external perimeter measure, while cable locks on laptops (D) and chassis locks on servers (E) are asset-level physical controls that protect individual devices rather than the external perimeter.

Exam trap

CC often tests whether candidates can distinguish between external perimeter controls and internal or endpoint controls, so the trap is selecting an internal control (like biometric readers) as an external perimeter measure.

91
MCQhard

An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?

A.Administrative access control
B.Logical access control
C.Compensating control
D.Physical access control
AnswerB

Account lockout is enforced through Group Policy settings processed by the domain controller, restricting access via software configuration rather than physical barriers. This makes it a logical access control, satisfying the scenario's requirement to limit system entry after repeated failed authentication attempts.

Why this answer

Logical access controls are software-based mechanisms that govern access to systems. Account lockout policies are logical controls.

92
MCQeasy

A hospital issues each nurse a unique username and a badge that is scanned at a workstation to prove the nurse's identity before any patient records can be opened. Which access control concept does scanning the badge to prove identity represent?

A.Authentication
B.Identification
C.Authorization
D.Accounting
AnswerA

Authentication verifies that the claimed identity matches the person presenting the credential. The badge scan supplies a factor that the system validates against the enrolled identity for that nurse, confirming the user is who the username claims. Only after this verification succeeds can the system decide authorization, so the scan is the authentication step in this scenario.

Why this answer

Authentication is the verification of a claimed identity, and the badge scan validates that the nurse is the person associated with the enrolled credential. Identification only asserts who someone claims to be, while authorization decides what that verified identity may do. Because the scenario emphasizes proving identity before opening records, the scan is the authentication step.

Exam trap

The trap here is confusing the act of claiming an identity with the act of proving it, which leads candidates to select identification instead of authentication.

93
Multi-Selectmedium

A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?

Select 1 answer
A.Separation of duties; risk of fraud
B.Defense in depth; risk of single point of failure
C.Need-to-know; risk of data exposure
D.Least privilege; risk of excessive permissions
E.Privileged access management; risk of account compromise
AnswersA

One employee both initiating and approving payments removes the independent check, letting fraudulent transactions pass unchallenged. Separation of duties requires these functions be split across different people, so the violation creates a direct fraud risk.

Why this answer

Separation of duties requires that critical tasks be split among multiple people so no single individual can complete a sensitive transaction end-to-end. Here, one employee can both initiate and approve a payment, violating that principle and creating a direct fraud risk since they could authorize unauthorized payments. This is a classic internal-controls failure in financial environments.

Exam trap

CC often tests the confusion between separation of duties and least privilege — both limit user power, but SoD is about splitting a workflow across people, while least privilege is about minimizing each person's permissions.

94
Multi-Selectmedium

A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)

Select 2 answers
A.Security guard at entrance
B.Smart card authentication for system access
C.Bollards at parking lot
D.Password policy enforcing complexity
E.Perimeter fence
AnswersB, D

Smart card authentication is a logical access control because it governs access through technical means — credentials and certificates validated by a system — rather than physical barriers. It satisfies the stem's requirement by restricting system access based on logical identity verification.

Why this answer

B is correct because smart card authentication is a logical (technical) access control that uses a credential and cryptographic verification to grant or deny access to systems and data. D is correct because a password policy enforcing complexity is a logical control that governs how users authenticate electronically, restricting access through technical rules. A is not correct because a security guard is a physical access control (personnel-based).

C is not correct because bollards are physical barriers used to control vehicle access. E is not correct because a perimeter fence is a physical access control.

Exam trap

CC often tests the physical-vs-logical distinction by including obvious physical controls (guards, fences, bollards) alongside subtle logical ones (smart cards, password policies) to see if candidates can classify correctly.

95
MCQhard

An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?

A.Controls and monitors privileged access
B.Provides a single sign-on for all users
C.Eliminates the need for passwords
D.Automates user provisioning for all accounts
AnswerA

PAM brokers privileged accounts through vaulting, session isolation and credential checkout, so administrative actions are both restricted and recorded. This controls and monitors privileged access, satisfying the stem's requirement for a primary benefit rather than general authentication or endpoint protection.

Why this answer

PAM solutions are designed to secure, control, and monitor privileged accounts — the accounts with elevated access such as root, domain admin, and service accounts. Core PAM capabilities include credential vaulting, session recording, just-in-time access, and approval workflows for privileged actions. The primary benefit is therefore controlling and monitoring privileged access to reduce the risk of misuse or compromise.

Exam trap

CC often tests the confusion between PAM and IGA/SSO — candidates pick 'automates user provisioning' or 'single sign-on' because those sound like identity benefits, but PAM is specifically about privileged account control and monitoring.

How to eliminate wrong answers

Option B is wrong because single sign-on (SSO) is a separate identity feature that improves user convenience across applications; PAM may integrate with SSO but SSO is not its primary benefit. Option C is wrong because PAM does not eliminate passwords — it typically vaults, rotates, and manages them, and may add passwordless or certificate-based access for privileged users, but password elimination is not its defining benefit. Option D is wrong because automated user provisioning is the domain of Identity Governance and Administration (IGA) or Identity Lifecycle Management tools, not PAM, which focuses on privileged accounts rather than all accounts.

96
MCQeasy

A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?

A.Authentication
B.Authorization
C.Accounting
D.Identification
AnswerA

Authentication is the process of verifying that a subject's claimed identity is genuine, typically by validating something the subject knows, has, or is. Entering a username and password and having the directory confirm them is the classic example of authentication. The system is proving the employee is who they claim to be before any access decision is made.

Why this answer

When a user supplies a username and password and the system validates them against stored credentials, the system is verifying the claimed identity. That verification step is authentication. Identification alone is just the claim of an identity, and authorization and accounting happen after authentication succeeds, so authentication is the concept being exercised here.

Exam trap

The trap here is treating the username as the whole event and choosing identification, when the presence of a validated password makes the process authentication.

97
MCQeasy

Which process involves verifying the identity of a user who claims to be a specific person?

A.Authorization
B.Authentication
C.Identification
D.Accounting
AnswerB

Authentication verifies a claimed identity by validating credentials such as passwords, tokens or biometrics against stored data. This directly satisfies the stem's requirement, distinguishing it from authorisation, which determines what an already-identified user may access.

Why this answer

Authentication is the process of verifying that a user's claimed identity is genuine, typically by validating credentials such as a password, token, or biometric factor against stored data. It answers the question 'Are you really who you say you are?' and occurs after identification but before authorization. This is the core definition tested in the CIA triad's access control model.

Exam trap

The trap here is confusing authentication with identification or authorization — candidates often pick 'identification' because both involve a user claiming an identity, but only authentication actually verifies it.

How to eliminate wrong answers

Option A is wrong because authorization determines what resources an authenticated user may access, not who they are. Option C is wrong because identification is merely the act of claiming an identity (e.g., entering a username), which precedes and does not verify authentication. Option D is wrong because accounting (auditing) tracks and logs user activity for accountability, not identity verification.

98
MCQeasy

Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?

A.Least privilege
B.Need-to-know
C.Separation of duties
D.Defense in depth
AnswerA

Least privilege restricts user access rights to the minimum set of permissions required to complete assigned job functions, directly satisfying the stem’s requirement to reduce the impact of a compromised account. By enforcing granular permission boundaries—such as read-only access to specific Microsoft Entra ID resources rather than full administrative roles—this principle limits lateral movement and data exposure if credentials are stolen.

Why this answer

Least privilege is the principle that users, processes, and systems should be granted only the minimum access rights required to perform their legitimate tasks, and no more. This limits the blast radius if an account is compromised, because the attacker inherits only the narrow permissions of that account. It is a foundational concept in access control and is explicitly required by standards like NIST SP 800-53 (AC-6).

Exam trap

The trap is conflating least privilege with need-to-know — both restrict access, but least privilege governs permissions/rights while need-to-know governs data classification access.

How to eliminate wrong answers

Option B is wrong because need-to-know is about restricting access to specific information based on job relevance, which is a subset of least privilege focused on data rather than permissions. Option C is wrong because separation of duties splits critical tasks among multiple people to prevent fraud, not to minimize individual permissions. Option D is wrong because defense in depth is a layered security strategy, not a permission-minimization principle.

99
MCQmedium

An account lockout policy is designed to mitigate which type of attack?

A.SQL injection
B.Man-in-the-middle
C.Phishing
D.Brute force
AnswerD

Brute force attacks repeatedly submit password guesses until one succeeds. Locking the account after five failures within 15 minutes halts that iterative guessing, because further attempts are refused regardless of correctness, directly mitigating the attack's core mechanism.

Why this answer

An account lockout policy locks a user account after a specified number of failed login attempts, which mitigates brute force attacks by preventing attackers from making unlimited password guesses. Brute force attacks rely on trying many combinations; lockout stops this after a few attempts.

Exam trap

CC often tests the purpose of account lockout, and candidates might confuse it with mitigating phishing or other attacks, but the primary target is brute force.

How to eliminate wrong answers

Option A is wrong because SQL injection is an attack on database queries, not mitigated by account lockout. Option B is wrong because man-in-the-middle attacks intercept communications, not prevented by account lockout. Option C is wrong because phishing tricks users into revealing credentials, and account lockout does not prevent phishing; it may even cause denial of service if attackers intentionally lock accounts.

100
Multi-Selectmedium

A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)

Select 2 answers
A.A firewall rule that blocks inbound traffic to the server subnet from the corporate network.
B.A locked cabinet that houses backup tapes and requires a key held by the storage administrator.
C.A mantrap with interlocking doors that admits one authenticated person at a time into the server hall.
D.A badge reader at the server hall door that logs the identity and timestamp of each entry.
E.A privacy filter applied to the administrator's monitor so bystanders cannot read displayed data.
AnswersC, D

A mantrap uses two sets of doors with interlocking controls so that only one authenticated individual can pass at a time, preventing tailgating into the server hall. Combined with authentication, it restricts who enters and can be integrated with logging. This directly addresses the goal of controlling physical entry to the protected space.

Why this answer

Physical access controls govern movement into protected spaces and often produce an audit trail. A badge reader authenticates the person and logs the entry, while a mantrap enforces one-person-at-a-time passage and prevents tailgating. Together they restrict who reaches the servers and create records of when entry occurred.

Firewalls, locked media cabinets, and monitor privacy filters protect other assets or confidentiality but do not control doorway access.

Exam trap

The trap here is counting any physical safeguard, such as a locked cabinet or privacy filter, as an entry control even though it does not restrict or log who enters the server hall.

101
MCQmedium

A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?

A.Account recertification
B.Least privilege
C.Separation of duties
D.Access revocation during offboarding
AnswerD

When an employee leaves, all access rights should be revoked as part of offboarding. Disabling the account is not sufficient if permissions remain on resources, because the account could be re-enabled or the permissions could be inherited by another account. The scenario shows that read and write permissions persisted, so the offboarding process failed to remove access properly.

Why this answer

Offboarding should include disabling the account and removing or transferring all associated permissions. The scenario shows that the account was disabled but its read and write permissions on the file server remained, indicating that access revocation was incomplete. Least privilege, separation of duties, and account recertification are valuable controls, but they do not directly describe the failure to strip permissions when the employee departed.

Exam trap

The trap here is assuming that disabling an account automatically removes its permissions, when in fact permissions often persist and must be explicitly revoked.

102
Multi-Selectmedium

Which TWO of the following are components of the identification and authentication process? (Select TWO.)

Select 2 answers
A.Password
B.Username
C.Group policy
D.Access control list (ACL)
E.Role-based access control (RBAC)
AnswersA, B

A password is the credential a subject supplies to prove claimed identity, making it the authentication component of the process. Identification occurs when the user presents a username or similar identifier, which the password then verifies against stored data.

Why this answer

The identification and authentication process consists of two distinct steps: identification, where a subject claims an identity, and authentication, where that claim is verified. Option B (Username) is correct because the username is the identifier — the claim of identity presented during the identification step. Option A (Password) is correct because the password is the authenticator — the secret credential verified against the stored value during the authentication step.

Option C (Group policy) is incorrect because it is a management mechanism for enforcing configuration and security settings, not a component of identification or authentication. Option D (Access control list, ACL) is incorrect because an ACL is an authorization mechanism that specifies which subjects may access which objects, operating after authentication completes. Option E (Role-based access control, RBAC) is incorrect because RBAC is an authorization model that grants permissions based on roles, not part of proving identity.

Exam trap

CC often tests the confusion between authentication components (username/password) and authorization mechanisms (ACL, RBAC, group policy), causing candidates to select authorization tools as authentication components.

103
MCQmedium

A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?

A.Separation of duties
B.Need-to-know
C.Defense in depth
D.Least privilege
AnswerD

Separating a standard account from an elevated one limits privileged access to tasks that genuinely require it, applying least privilege. This satisfies the stem's scenario by preventing daily activities, such as browsing email, from running with administrative rights.

Why this answer

The principle of least privilege states that users should be granted only the minimum levels of access—or permissions—necessary to perform their job functions. By using a regular account for daily work and a separate elevated account only when needed, the administrator is limiting the exposure of privileged access, thus applying least privilege.

Exam trap

The trap is that candidates might confuse least privilege with separation of duties; both involve limiting access, but least privilege is about minimizing permissions, while separation of duties is about dividing tasks among multiple people.

How to eliminate wrong answers

Option A is wrong because separation of duties involves dividing responsibilities among different individuals to prevent fraud or errors, not about using separate accounts for different privilege levels. Option B is wrong because need-to-know is about limiting access to information based on necessity, typically in security clearances, not about account privileges. Option C is wrong because defense in depth is a layered security approach, not a specific principle about account usage.

104
MCQmedium

A small accounting firm wants to grant access to its tax software based on the department a user belongs to, rather than assigning permissions to each person individually. Which access control model should the firm implement to meet this requirement?

A.Rule-based access control
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Discretionary access control (DAC)
AnswerB

RBAC assigns permissions to roles such as Tax Preparer or Auditor, and users receive access by being placed in the appropriate role. The firm wants access determined by department membership, which maps directly to role assignment, so permissions stay consistent as individuals move. This satisfies the requirement without per-user permission management.

Why this answer

Role-based access control grants permissions to roles and then assigns users to those roles, so access follows a person's function rather than being set individually. Because the firm wants tax software access determined by department membership, defining roles and assigning users to them delivers the required consistency and reduces administrative effort when staff change positions.

Exam trap

The trap here is assuming any centralized permission scheme is role-based, when discretionary and rule-based models also centralize some control but not through role membership.

105
Multi-Selectmedium

Which THREE are recommended practices for password policies according to current guidelines?

Select 3 answers
A.Check passwords against lists of known breached passwords
B.Require passwords at least 8 characters long
C.Require at least one uppercase letter, one number, and one special character
D.Allow passwords up to 64 characters
E.Force password changes every 30 days
AnswersA, B, D

Checking passwords against breached-password lists blocks credentials already exposed in known data breaches, directly satisfying the guideline to screen for compromised passwords. Microsoft Entra ID implements this natively through its banned-password list, which is populated from breach data and automatically rejects matching entries during password set or reset.

Why this answer

Option A is correct because current NIST SP 800-63B guidance requires screening new passwords against lists of known compromised or breached passwords (such as those from Have I Been Pwned) and rejecting any that match. Option B is correct because NIST sets the minimum password length at 8 characters when a password is used as a single-factor authenticator. Option D is correct because NIST recommends permitting passwords up to at least 64 characters, allowing the use of long passphrases and password managers.

Option C is not recommended because composition rules (mixing uppercase, numbers, and special characters) are now discouraged as they push users toward predictable patterns. Option E is not recommended because arbitrary periodic rotation (for example, every 30 days) is discouraged; changes should only be forced when there is evidence of compromise.

Exam trap

The trap here is that many candidates still believe traditional complexity and frequent expiration are best practices, but current guidelines (e.g., NIST) explicitly advise against them, favoring length and breach checks instead.

106
MCQhard

A financial services firm grants a contractor temporary access to a trading application for a 90-day engagement. The security team wants the access to expire automatically without manual intervention, and also wants the contractor's manager to periodically confirm the access is still required. Which combination of access control practices best satisfies both requirements?

A.Role-based access control combined with discretionary access control
B.Account lockout thresholds combined with password complexity requirements
C.Time-based account expiration combined with periodic access reviews
D.Single sign-on combined with multifactor authentication
AnswerC

Account expiration enforces a hard stop date, so the contractor's credentials stop working when the 90-day engagement ends without anyone needing to remember to disable them. Periodic access reviews require the manager to reconfirm that the access remains justified, catching situations where the engagement is extended unnecessarily or where the scope has drifted. Together they address both automatic termination and ongoing validation of need.

Why this answer

Temporary access should be bounded in time and periodically justified. An account expiration date guarantees the access ends automatically at the close of the engagement, while periodic access reviews force the manager to reconfirm that the contractor still needs the trading application. The other combinations improve authentication strength or permission structure but do not provide automatic expiry or ongoing attestation.

Exam trap

The trap here is treating strong authentication controls as if they also manage the access lifecycle, when expiry and recertification are separate administrative controls.

107
MCQhard

A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?

A.Role-Based Access Control (RBAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Attribute-Based Access Control (ABAC)
AnswerB

MAC enforces access decisions from system-controlled labels rather than from user discretion. Subjects receive clearances and objects receive classifications, and the system permits access only when the clearance dominates the label. Because users cannot alter labels or extend access to others, this precisely matches the described enforcement, including the dominance rule for reading.

Why this answer

The system bases every access decision on system-assigned classification labels and user clearances, and users cannot modify those labels or delegate access. That combination of non-discretionary, label-driven enforcement is Mandatory Access Control. The dominance rule described, where clearance must dominate the object label for read access, is a hallmark of mandatory models such as Bell-LaPadula.

Exam trap

The trap here is focusing on the word 'clearance' and picking role-based control, when the decisive clue is that labels are system-enforced and users cannot delegate access.

108
MCQhard

A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?

A.Visitor sign-in and escort policy only
B.A single high-tech lock on the server room door
C.A strong password policy for all employees
D.Perimeter fencing, access badges at building entrance, biometric reader on server room, and cable locks on servers
AnswerD

Each layer compensates if an earlier one fails: fencing delays intrusion, badges filter entrants, biometrics restrict the server room, and cable locks stop physical theft. This satisfies the defence-in-depth requirement by combining deterrence, detection and delay across independent boundaries.

Why this answer

Defense in depth involves implementing multiple layers of security controls so that if one layer fails, others still provide protection. The combination of perimeter fencing, access badges at the building entrance, biometric reader on the server room, and cable locks on servers represents multiple physical security layers, from the outer perimeter to the individual server level. This is a classic example of defense in depth.

Exam trap

The trap is that candidates might choose a single strong control (like a high-tech lock) thinking it is sufficient, but defense in depth requires multiple, diverse layers; also, they might confuse logical controls with physical controls.

How to eliminate wrong answers

Option A is wrong because a visitor sign-in and escort policy only is a single layer of control and does not provide depth. Option B is wrong because a single high-tech lock on the server room door is a single point of failure and does not represent multiple layers. Option C is wrong because a strong password policy is a logical control, not a physical security control, and does not address physical defense in depth.

109
MCQmedium

An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?

A.HTTP
B.FTP
C.SNMP
D.LDAP
AnswerD

LDAP is the directory access protocol Active Directory natively speaks, providing the query and modify operations the stem requires. Clients bind to the directory and issue search, add, modify, and delete requests over TCP port 389 or 636. Kerberos handles authentication, but LDAP performs the directory read and write operations.

Why this answer

Active Directory primarily uses LDAP (Lightweight Directory Access Protocol) to query and modify its directory services. LDAP defines the structure and operations for accessing directory information, and AD implements LDAP v3 as its core access protocol on port 389 (and 636 for LDAPS). Administrative tools and applications use LDAP queries to read and write user, group, and computer objects.

Exam trap

The trap is confusing LDAP with Kerberos — candidates may know AD uses Kerberos for authentication and incorrectly select a different protocol for directory queries, but LDAP is specifically the query/modify protocol.

How to eliminate wrong answers

Option A is wrong because HTTP is the protocol for web traffic, not directory queries, though AD does expose some web-based services like AD FS and Web Enrollment. Option B is wrong because FTP transfers files and has no role in directory service queries. Option C is wrong because SNMP is used for monitoring and managing network devices, not for querying directory objects.

110
MCQeasy

Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?

A.Standard user account
B.Service account
C.Admin/root account
D.Guest account
AnswerC

Admin and root accounts hold unrestricted control over systems and data, so their compromise yields immediate full impact. Separate daily-use accounts ensure routine browsing and email never expose these credentials, satisfying the strict-control requirement for the highest-risk account type.

Why this answer

Admin/root accounts have unrestricted privileges over systems, data, and configurations, making them the highest-value target for attackers — compromise grants full control. Best practice is to protect them with strict controls (MFA, privileged access workstations, just-in-time elevation) and use separate, non-privileged accounts for daily tasks like email and browsing.

Exam trap

The trap is overthinking 'service account' as the highest risk — while service accounts are risky, the exam expects admin/root as the top-tier account requiring separate daily-use accounts and strict controls.

How to eliminate wrong answers

Option A is wrong because standard user accounts have limited privileges and, while still targets, do not grant the broad control that admin/root accounts do. Option B is wrong because service accounts are high-risk in a different way (often non-interactive, hard-coded credentials), but they are not the top-tier risk that admin/root represents. Option D is wrong because guest accounts have minimal privileges by design and are typically disabled; they are not the highest-risk account type.

111
MCQmedium

A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Rule-Based Access Control
AnswerB

RBAC grants permissions to roles rather than to individual users, and users receive permissions by being assigned to a role. Creating a 'Pediatric Nurse' role and assigning nurses to it directly solves the rotation and administration problem described. When a nurse moves departments, only the role assignment changes, and permissions follow automatically, reducing errors.

Why this answer

The hospital needs permissions tied to job functions rather than to individual accounts. Role-Based Access Control creates roles, assigns permissions to those roles, and then assigns users to roles, so rotating staff only requires changing the role assignment. This reduces administrative errors, supports least privilege at the role level, and scales cleanly as departments and duties change.

Exam trap

The trap here is assuming that any centralized or administrator-managed model automatically groups permissions by job function, when only RBAC assigns permissions to roles that users then occupy.

112
MCQmedium

Which of the following is a recommended practice for password security according to NIST SP 800-63?

A.Require frequent password changes every 30 days
B.Use a minimum of 8 characters and check against breached password lists
C.Set maximum password age to 90 days
D.Enforce complex passwords with special characters
AnswerB

NIST SP 800-63 recommends an eight-character minimum and screening new passwords against breached-password lists, blocking compromised credentials. This satisfies the stem's requirement by reflecting current guidance that favours length and breach checking over forced periodic rotation and composition rules.

Why this answer

NIST SP 800-63B recommends a minimum of 8 characters and checking new passwords against lists of commonly used or breached passwords. It also advises against arbitrary complexity rules and frequent expiration, focusing instead on length and breach checks. This approach balances usability with security by preventing weak, compromised passwords.

Exam trap

The trap is the common belief that frequent password changes and complexity requirements are best practices; the exam tests knowledge of updated NIST guidance that discourages these in favor of length and breach checks.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-63B explicitly discourages frequent password changes (e.g., every 30 days) as they lead to weaker passwords and user frustration. Option C is wrong because setting a maximum password age of 90 days is also discouraged by NIST for the same reason. Option D is wrong because enforcing complex passwords with special characters is not a NIST recommendation; NIST advises against composition rules and instead promotes length and breach checks.

113
MCQmedium

A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?

A.Need-to-know
B.Least privilege
C.Defense in depth
D.Separation of duties
AnswerA

Accessing another department's files breaches need-to-know, which restricts data to individuals whose specific duties require it. Least privilege governs permission scope, not data relevance, so it does not fit this scenario. Need-to-know satisfies the stem's constraint: a user reaching files outside their own department.

Why this answer

The need-to-know principle restricts access to information only to individuals who require it to perform their specific job duties. A user accessing files in a department they do not work in violates this principle because they have no legitimate need for that information.

Exam trap

The trap here is confusing need-to-know with least privilege; candidates often pick least privilege because both involve limiting access, but need-to-know is about information relevance to job duties, not system permissions.

How to eliminate wrong answers

Option B is wrong because least privilege focuses on granting the minimum system permissions necessary for a role, not on restricting access based on job function or information relevance. Option C is wrong because defense in depth is a layered security strategy, not a specific access control principle about individual access rights. Option D is wrong because separation of duties prevents one person from controlling all aspects of a critical process, which is unrelated to accessing another department's files.

114
MCQhard

A software company wants contractors to access an internal code repository only during their contracted hours and only from company-managed laptops. The repository administrator should implement which type of access control to meet these conditions?

A.Rule-based access control, by evaluating time-of-day and managed-device conditions
B.Discretionary access control, by letting the repository owner approve each contractor
C.Role-based access control, by creating a Contractor role with read access
D.Mandatory access control, by labeling the repository as confidential and requiring clearance
AnswerA

Rule-based access control decides access by evaluating conditions at request time. A rule can require that the current time fall within contracted hours and that the connecting device be enrolled and compliant in the management system. Both constraints in the scenario are conditions, making rule-based access control the appropriate model to enforce them dynamically.

Why this answer

The requirements are conditions evaluated when access is requested: the clock must be inside contracted hours, and the device must be company-managed. Rule-based access control inspects exactly such attributes at decision time, enforcing both constraints together. Role, discretionary, and mandatory models govern who may access what, but none of them natively evaluate time-of-day or device posture.

Exam trap

The trap here is choosing a role-based model because contractors form a group, missing that the scenario's constraints are contextual conditions rather than job-function permissions.

115
MCQmedium

A financial services firm assigns permissions based on each employee's role in the HR system. When an employee transfers from accounting to marketing, the HR record changes and the employee's access is automatically updated to match the marketing role. Which access control model is the firm using?

A.Discretionary access control (DAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Rule-based access control
AnswerB

RBAC grants permissions to roles rather than individuals, and users receive access through role assignment. When the employee moves from accounting to marketing, the role changes and permissions follow automatically. This matches the scenario precisely, where HR role data drives access updates without per-user permission edits.

Why this answer

Role-based access control centralizes permissions in roles and assigns users to those roles. When an employee's job function changes, updating the role assignment automatically adjusts access, which reduces administrative overhead and errors. The scenario's automatic permission change driven by HR role data is the defining characteristic of RBAC in enterprise environments.

Exam trap

The trap here is confusing role-based access control with rule-based access control because both use the word rules or roles in casual descriptions.

116
MCQmedium

A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerD

Separation of duties splits a critical transaction across multiple people so no single employee controls it end to end. Requiring one person to raise a payment and another to approve it directly satisfies the stem's constraint: preventing one employee from both approving and disbursing funds.

Why this answer

Separation of duties is the principle that no single individual should have control over all aspects of a critical process. By preventing one employee from both approving and disbursing payments, the company ensures that multiple people are involved, reducing the risk of fraud or error.

Exam trap

The trap is confusing separation of duties with least privilege; candidates may pick least privilege because both involve limiting access, but separation of duties specifically addresses dividing tasks among multiple people to prevent fraud.

How to eliminate wrong answers

Option A is wrong because need-to-know is about restricting access to information based on job requirements, not dividing tasks. Option B is wrong because defense in depth is a layered security strategy, not a specific task-division principle. Option C is wrong because least privilege limits permissions to the minimum necessary, but does not address the separation of approval and disbursement tasks.

117
MCQmedium

A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?

A.Separation of duties
B.Need to know
C.Least privilege
D.Defense in depth
AnswerB

Need to know limits access to only the specific information a user requires to perform their duties. The teller needs records for their own branch's customers to serve them, but has no legitimate need to view customers at other branches. Restricting the teller's visibility to only the records necessary for their work is the essence of the need-to-know principle.

Why this answer

Need to know restricts access to only the information a user requires for their job, which is why the teller sees only their branch's customers. Least privilege limits the types of permissions granted, separation of duties splits tasks among users, and defense in depth layers controls. The record-level restriction described maps to need to know.

Exam trap

The trap here is choosing least privilege because access is limited, when the scenario is specifically about limiting which data records a user can see, which is need to know.

118
MCQeasy

Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?

A.Defense in depth
B.Least privilege
C.Separation of duties
D.Need-to-know
AnswerB

Least privilege grants each user only the minimum permissions their job requires, limiting blast radius if credentials are compromised. It directly satisfies the stem's constraint of minimum necessary access, unlike broader models such as role-based or discretionary access.

Why this answer

The principle of least privilege states that users (and processes) should be granted only the minimum permissions necessary to perform their job functions, reducing the attack surface and limiting the blast radius of a compromised account. It is a foundational access-control principle in cybersecurity and is explicitly tested in the ISC2 CC exam. Defense in depth, separation of duties, and need-to-know are related but distinct concepts.

Exam trap

The CC exam often tests the confusion between least privilege and need-to-know — both minimize access, but least privilege is about permissions/rights while need-to-know is about information access based on a specific requirement.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered-security strategy using multiple overlapping controls (firewalls, IDS, encryption, policies) rather than a permission-minimization principle. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error (e.g., one person approves, another pays), not about minimizing permissions. Option D is wrong because need-to-know restricts access to information based on whether a person requires it for a specific task — it is closely related but applies to data/information access rather than the broader permission scope of least privilege.

119
MCQmedium

A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?

A.Something you know
B.Something you are
C.Something you have
D.Somewhere you are
AnswerC

Something you have is a possession factor, and the smart card is a physical token the employee holds and inserts into a reader. The card performs cryptographic operations with a private key that never leaves it, proving possession. This is the classic example of a possession factor used in multifactor authentication, distinct from memorized secrets or biometric traits.

Why this answer

A smart card is a possession factor because the employee must physically hold and present the token, and the embedded private key enables cryptographic proof that the token is present. It is commonly combined with a PIN or password to achieve multifactor authentication, pairing what the user has with what the user knows.

Exam trap

The trap here is treating the smart card as a knowledge factor simply because it may be unlocked with a PIN, when the device itself demonstrates possession rather than memorized knowledge.

120
Multi-Selecthard

A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)

Select 3 answers
A.Requiring access badges to enter the building
B.Single sign-on (SSO) for all applications
C.Using a single firewall for all network traffic
D.Encrypting data at rest
E.Fencing around the building
AnswersA, D, E

Access badges enforce authentication at the building entry point, verifying identity before anyone reaches the data centre. It satisfies the defense in depth constraint by adding a physical access control layer that complements network, encryption and administrative safeguards.

Why this answer

Option A is correct because requiring access badges to enter the building is a physical (premises) access control that restricts who can reach the data center, forming the outermost layer of defense in depth. Option D is correct because encrypting data at rest protects stored data (e.g., AES-256 on disks or databases) so that even if physical or logical access is gained, the data remains unreadable. Option E is correct because fencing around the building is a perimeter physical control that deters and delays intrusion, complementing badge access as an additional defensive layer.

Option B does not belong because SSO centralizes authentication and can actually reduce the number of independent barriers, and it is an identity convenience/control rather than a distinct defense-in-depth layer. Option C does not belong because a single firewall for all network traffic is a single point of failure and contradicts defense in depth, which requires multiple, diverse, and redundant controls.

Exam trap

The trap is selecting convenient or familiar controls (SSO, a single firewall) that sound secure but actually reduce layering, while missing that defense in depth requires diverse physical and data-level controls.

121
MCQhard

A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerC

Least privilege grants only the rights needed for the current task, so the administrator uses a standard account daily and elevates only for maintenance. This limits exposure from compromised sessions, matching the stem's separate-account practise.

Why this answer

The scenario describes using a separate administrative account with elevated privileges only for system maintenance, while using a standard user account for daily activities like email. This aligns with the principle of least privilege, which dictates that users should be granted only the minimum access rights necessary to perform their job functions, and only for the duration needed. By not using the admin account for routine tasks, the administrator reduces the attack surface and potential damage from accidental or malicious actions.

Exam trap

The trap here is confusing least privilege with separation of duties; candidates often think that using two different accounts is separation of duties, but separation of duties requires two people, not two accounts for one person.

How to eliminate wrong answers

Option A is wrong because need-to-know is about restricting access to information based on whether a person requires it to perform their duties, not about limiting privileges of accounts. Option B is wrong because defense in depth involves multiple layers of security controls, not specifically about using separate accounts for different tasks. Option D is wrong because separation of duties requires dividing critical tasks among multiple people to prevent fraud, not about an individual using different accounts for different activities.

122
Multi-Selectmedium

Which THREE of the following are best practices for privileged account management? (Select THREE.)

Select 3 answers
A.Use a Privileged Access Management (PAM) solution to monitor and control admin access
B.Use the same admin account for daily tasks to simplify management
C.Create a separate admin account for administrative tasks, distinct from daily use account
D.Grant administrators full access to all systems at all times for convenience
E.Apply the principle of least privilege to administrative accounts
AnswersA, C, E

A PAM solution vaults credentials, brokers sessions and logs administrative activity, directly satisfying the monitoring and control requirement for privileged account management. It removes standing access by checking out credentials per session, giving accountability and auditability that shared or unmanaged admin accounts lack.

Why this answer

Option A is correct because a Privileged Access Management (PAM) solution provides vaulting, session monitoring, recording, and just-in-time elevation of administrative credentials, which are core best practices for controlling and auditing privileged access. Option C is correct because separating administrative accounts from everyday user accounts prevents credential theft from routine activities like email and web browsing from directly yielding privileged access, and it supports non-repudiation of admin actions. Option E is correct because applying the principle of least privilege ensures administrators receive only the rights required for their specific role, reducing the attack surface and limiting lateral movement if an admin account is compromised.

Option B is not a best practice because reusing a single admin account for daily tasks exposes high-privilege credentials to phishing, malware, and credential-dumping attacks. Option D is not a best practice because granting permanent full access to all systems violates least privilege and removes accountability, making misuse or compromise far more damaging.

Exam trap

The trap is selecting convenience-based options (same account, full access) that sound efficient but violate least privilege and separation of duties, which are core to privileged account management.

123
MCQeasy

An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?

A.Separation of duties
B.Defense in depth
C.Least privilege
D.Need-to-know
AnswerA

Separation of duties splits a critical transaction across two distinct individuals so no single person controls the whole process. Requiring one employee to initiate and a manager to approve enforces this split, preventing fraud or undetected error.

Why this answer

Separation of duties (SoD) is the principle that no single individual should have enough privileges to complete a sensitive transaction alone; it requires splitting critical tasks among multiple people. Here, one employee initiates and a different manager approves, which is the textbook definition of SoD. It prevents fraud and errors by ensuring collusion is needed to abuse the process.

Exam trap

The trap is confusing separation of duties with least privilege; both involve limiting access, but only SoD requires multiple distinct people to complete one sensitive action, which is the key differentiator the exam tests.

How to eliminate wrong answers

Option B is wrong because defense in depth refers to layering multiple security controls (firewalls, IDS, encryption) so that if one fails, others still protect the asset; it is not about splitting a single transaction between people. Option C is wrong because least privilege means granting users only the minimum access needed for their job, not requiring two people for one action. Option D is wrong because need-to-know restricts access to information based on job relevance, which is about data confidentiality, not about requiring dual approval for a transaction.

124
MCQmedium

A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?

A.Need-to-know
B.Defense in depth
C.Separation of duties
D.Least privilege
AnswerC

Separation of duties splits a sensitive transaction across two people so no single employee holds end-to-end authority. Requiring two managers to jointly approve orders above $10,000 enforces exactly this: the approval capability is divided, preventing one person from committing fraud or error unchecked.

Why this answer

Separation of duties is a security principle that prevents a single individual from having control over all aspects of a critical transaction. By requiring two managers to jointly approve a purchase order over $10,000, the company ensures that no single person can commit fraud or error without detection. This is a classic example of separation of duties, also known as segregation of duties.

Exam trap

The trap is that candidates may confuse separation of duties with least privilege or defense in depth, but the key differentiator is the requirement for multiple people to complete a task, which is the essence of separation of duties.

How to eliminate wrong answers

Option A is wrong because need-to-know is about limiting access to information based on job requirements, not about splitting approval authority. Option B is wrong because defense in depth involves multiple layers of security controls, not specifically the division of responsibilities. Option D is wrong because least privilege means giving users only the minimum access necessary to perform their jobs, not requiring multiple approvals.

125
MCQmedium

A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?

A.Technical access control
B.Physical access control
C.Administrative access control
D.Logical access control
AnswerB

Physical access control governs entry to premises and movement within them, matching the reception sign-in, badge issue and escort described. The badge acts as the credential enforcing that control, while the escort constrains where the visitor may go. Logical controls such as Microsoft Entra ID govern systems, not building entry.

Why this answer

The scenario describes a visitor signing in, receiving a badge, and being escorted, which are all physical measures to control access to the building. Physical access control encompasses mechanisms like badges, locks, guards, and escorts that restrict physical entry to facilities. Therefore, this process is part of physical access control.

Exam trap

The trap here is confusing physical access control with administrative or logical controls; candidates might think that because a policy is involved (signing in), it's administrative, but the actual controls are physical.

How to eliminate wrong answers

Option A is wrong because technical access control involves technology-based controls like firewalls, encryption, or authentication systems, not physical measures. Option C is wrong because administrative access control refers to policies, procedures, and training, such as background checks or security awareness, not the actual physical entry process. Option D is wrong because logical access control deals with access to digital resources like files, databases, or networks, not physical spaces.

126
MCQhard

A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?

A.Discretionary access control (DAC), because repository owners can set permissions as they see fit
B.Mandatory access control (MAC), because labels and clearances prevent unauthorized modifications
C.Rule-based access control, because conditions such as branch protection rules can restrict actions
D.Role-based access control (RBAC), because permissions are tied to job functions like developer and release manager
AnswerD

RBAC assigns permissions to roles and users to roles, so developers receive read and commit rights while the release manager receives tag creation rights. Because the rules are defined centrally by role rather than by repository ownership, they apply consistently to everyone. This matches the company's requirement that the separation be enforced regardless of who owns the repository.

Why this answer

Role-based access control defines permissions for roles and assigns users to those roles, so developers and the release manager receive exactly the rights their job functions require. Because the rules are centrally defined rather than owner-controlled, they are enforced consistently. Discretionary control would leave decisions to owners, mandatory control relies on labels, and rule-based control evaluates environmental conditions.

Exam trap

The trap here is selecting rule-based access control because branch protection sounds like a rule, when the scenario is really about permissions assigned by job function.

127
MCQmedium

A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?

A.Need-to-know
B.Least privilege
C.Separation of duties
D.Defense in depth
AnswerC

Separation of duties splits a sensitive transaction across two distinct identities so no single employee can complete it alone. The stem's constraint — one employee initiates, a different employee approves transfers over $10,000 — is satisfied precisely because authorisation is divided between separate people, preventing unilateral fraud.

Why this answer

The policy requires two different employees to approve wire transfers over $10,000, with one initiating and another approving. This is a classic example of separation of duties, which ensures that no single individual has the authority to complete a critical task alone, thereby reducing the risk of fraud or error. By splitting the task between two people, the organization enforces a system of checks and balances.

Exam trap

The trap here is confusing separation of duties with least privilege or need-to-know; candidates might think that because two people are involved, it's about limiting access, but it's specifically about dividing duties to prevent fraud.

How to eliminate wrong answers

Option A is wrong because need-to-know is about limiting access to information based on job requirements, not about dividing tasks between people. Option B is wrong because least privilege is about granting minimal permissions necessary for a role, not about requiring multiple approvals. Option D is wrong because defense in depth involves multiple layers of security controls, not specifically the division of duties among personnel.

128
MCQeasy

A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?

A.Physical access control
B.Logical access control
C.Administrative control
D.Technical control
AnswerA

Signing in, presenting identification and wearing a visitor badge are tangible measures regulating who enters the building. They restrict human movement through the facility, which defines physical access control rather than logical or administrative control.

Why this answer

Physical access control governs access to tangible facilities, buildings, rooms, and equipment, and the scenario describes exactly that: a visitor signing in, showing ID, and wearing a badge to enter a company building. These are physical safeguards designed to control who can enter a physical space. Logical, administrative, and technical controls address different domains such as systems, policies, and technology enforcement.

Exam trap

The trap here is conflating physical controls with administrative or technical controls because visitor sign-in involves a procedure (administrative) and a badge system (technical), but the scenario's core is controlling physical entry.

How to eliminate wrong answers

Option B is wrong because logical access control governs access to digital resources such as networks, applications, and data, not physical entry to a building. Option C is wrong because administrative controls are policy and procedure-based (e.g., security awareness training, background checks, separation of duties) rather than the physical sign-in and badge process itself. Option D is wrong because technical controls are technology-enforced mechanisms like firewalls, encryption, and authentication systems, which do not describe a visitor sign-in and badge procedure.

129
MCQhard

An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?

A.Passwords should be exactly 8 characters with at least one special character
B.Passwords should be changed every 30 days
C.Complexity requirements are more important than length
D.Length over complexity and no periodic changes
AnswerD

NIST guidance favours longer passphrases over forced complexity and drops mandatory periodic rotation, since length resists cracking while frequent changes push users toward predictable patterns. A 15-character minimum with no complexity rules and no expiry matches this modern approach.

Why this answer

Current NIST SP 800-63B guidance recommends favoring password length over complexity and eliminating forced periodic rotation, because long passphrases resist brute-force and dictionary attacks better than short complex strings, and frequent changes lead users to predictable patterns (e.g., Password1!, Password2!). A 15-character minimum with no complexity rules and no forced expiration aligns with this modern best practice.

Exam trap

CC often tests whether candidates still hold the legacy belief that complexity and frequent rotation are the gold standard, when current NIST guidance explicitly reverses that in favor of length and no forced expiration.

How to eliminate wrong answers

Option A is wrong because 8 characters with one special character is far below current minimum length recommendations and reflects outdated complexity-first thinking. Option B is wrong because forcing changes every 30 days contradicts NIST guidance, which found periodic rotation degrades security by encouraging weak, predictable increments. Option C is wrong because it inverts the modern recommendation — length, not complexity, is the dominant factor in resisting offline cracking and guessing attacks.

130
MCQhard

A defense contractor classifies documents as Public, Internal, Secret, and Top Secret. A user with Secret clearance attempts to open a Top Secret document and is denied, while a user with Top Secret clearance can open both Top Secret and Secret documents. Which access control model does this behavior describe?

A.Rule-based access control, because a fixed rule set decides every access request.
B.Role-based access control, because permissions follow the user's assigned job role.
C.Mandatory access control, because access is determined by comparing the subject's clearance to the object's classification label.
D.Discretionary access control, because the document owner decides who may read each file.
AnswerC

Mandatory access control bases every decision on labels assigned to subjects and objects, and the operating system enforces those labels regardless of user intent. Clearance must dominate classification for read access, which explains why Secret cannot read Top Secret while Top Secret can read Secret. This label-driven dominance rule is the hallmark of mandatory access control.

Why this answer

Mandatory access control relies on sensitivity labels attached to objects and clearances assigned to subjects, with the system enforcing the relationship. A subject may read an object only when their clearance dominates the object's classification, which is exactly why Secret cannot reach Top Secret and Top Secret can reach Secret. Users cannot alter these labels, making enforcement mandatory rather than discretionary.

Exam trap

The trap here is treating any hierarchical permission scheme as role-based access control when the deciding factor is actually data classification labels.

131
MCQeasy

What is the difference between identification and authentication?

A.Identification proves identity; authentication claims identity
B.They are the same thing
C.Identification uses passwords; authentication uses biometrics
D.Identification claims identity; authentication proves identity
AnswerD

Identification presents a claimed identity, such as a username, while authentication verifies that claim through credentials or factors, proving the subject genuinely owns that identity. This distinction satisfies the stem's requirement to separate the assertion of identity from its cryptographic or knowledge-based validation, matching how Microsoft Entra ID processes sign-ins.

Why this answer

Identification is the process of claiming an identity, such as providing a username. Authentication is the process of proving that claimed identity, typically by providing a password, token, or biometric. Therefore, identification claims identity, and authentication proves it.

Exam trap

The trap is the common misconception that identification and authentication are interchangeable or that identification proves identity. Candidates may confuse the two, especially under time pressure.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: identification does not prove identity; it claims it. Option B is wrong because identification and authentication are distinct steps in access control. Option C is wrong because it incorrectly associates identification with passwords and authentication with biometrics; both can use various factors, and the distinction is about claiming versus proving.

132
MCQmedium

A hospital's IT team assigns each doctor a unique smart card that must be inserted before the workstation unlocks, and the card's embedded certificate is validated against the hospital's internal certificate authority. Which access control process does the smart card insertion and certificate validation represent?

A.Accounting
B.Authorization
C.Authentication
D.Identification
AnswerC

Authentication verifies that a claimed identity is genuine. Inserting the smart card supplies something the doctor has, and validating its embedded certificate against the hospital's internal certificate authority proves the credential is trusted. This process confirms the doctor is who the card claims, which is precisely the definition of authentication in the access control lifecycle.

Why this answer

The smart card provides a possession factor, and the certificate authority validates that the credential is genuine and trusted. This verification of a claimed identity is the definition of authentication. Authorization and accounting occur later in the process, while identification is only the initial claim of an identity without proof.

Exam trap

The trap here is confusing identification with authentication, assuming that presenting a card or claiming an identity by itself constitutes proof of who the user is.

133
MCQmedium

A hospital's IT team wants to ensure that nurses can access patient records only during their assigned 12-hour shifts, even if their credentials are valid around the clock. Which access control model should the team implement to enforce this time-based restriction?

A.Discretionary Access Control (DAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Role-Based Access Control (RBAC)
AnswerB

ABAC evaluates attributes of the subject, object, action, and environment, including time-of-day and shift schedule. By defining a policy that permits access only when the current time falls within the nurse's assigned shift, ABAC directly enforces the temporal restriction. This makes it the appropriate model for dynamic, context-aware conditions such as shift-based access.

Why this answer

Attribute-Based Access Control evaluates environmental attributes such as current time and shift assignment alongside subject and object attributes. This allows the hospital to enforce a policy that grants patient-record access only during a nurse's scheduled shift, even when credentials remain valid. Role-Based Access Control, Mandatory Access Control, and Discretionary Access Control do not natively enforce time-of-day conditions, so they fail to meet the requirement.

Exam trap

The trap here is assuming that Role-Based Access Control automatically includes time-of-day restrictions because roles are tied to job functions.

134
Multi-Selecteasy

An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?

Select 2 answers
A.Identification and authentication
B.Need-to-know
C.Separation of duties
D.Least privilege
E.Defense in depth
AnswersB, D

Need-to-know restricts access to information strictly required to perform a role. The employee's job role did not require the confidential document, yet their account held read access to its folder, so access was granted beyond job necessity, violating this principle.

Why this answer

The scenario describes an employee who could read a confidential document unrelated to their job role, which directly violates the need-to-know principle (B) because access to information should be granted only to those who require it to perform their duties. It also violates the principle of least privilege (D), since the account was granted read access to a folder beyond the minimum permissions necessary for the employee's role. Identification and authentication (A) is not violated because the employee's account was properly identified and authenticated; the issue is authorization, not proving identity.

Separation of duties (C) is not implicated because no single individual was given control over multiple conflicting tasks or stages of a critical process. Defense in depth (E) is not violated because the scenario does not describe a failure of layered controls; it describes excessive permissions granted to an account.

Exam trap

The trap is confusing need-to-know with least privilege or selecting unrelated concepts like separation of duties. Candidates might think authentication was violated, but the employee used their own credentials.

135
Multi-Selectmedium

A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)

Select 2 answers
A.Access badges at building entrance
B.Biometric reader on server room door
C.Cable locks on laptops
D.Fencing around the property
E.Lighting in the parking lot
AnswersD, E

Fencing around the property is a perimeter physical control because it establishes the outermost boundary of the site, deterring and delaying unauthorised access before an intruder reaches the building. It satisfies the scenario's requirement for controls operating at the external perimeter, unlike interior measures such as locks on server-room doors.

Why this answer

Option D (fencing around the property) is correct because fencing is a classic perimeter control that establishes a physical boundary and deters or delays unauthorized entry to the site. Option E (lighting in the parking lot) is correct because exterior lighting is a perimeter control that illuminates the outer grounds, deterring intruders and enabling surveillance of approaches to the facility. Option A (access badges at building entrance) is not a perimeter control but an access control at a building entry point, which is a more interior layer of defense.

Option B (biometric reader on server room door) is an interior access control protecting a high-value asset, not the site perimeter. Option C (cable locks on laptops) is an asset-level physical control for portable devices, not a perimeter control.

Exam trap

The trap here is conflating 'physical control' with 'perimeter control' — badges, biometrics, and cable locks are all physical, but only fencing and exterior lighting sit at the property perimeter, so candidates who just scan for 'physical' pick the wrong two.

136
MCQmedium

A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?

A.Mandatory access control (MAC)
B.Rule-based access control
C.Discretionary access control (DAC)
D.Role-based access control (RBAC)
AnswerD

Role-based access control grants permissions to roles, and users receive permissions by being assigned to a role. In this scenario the job title acts as the role, and changing the title automatically changes access. This central administration of permissions through roles, rather than per-user grants, is the defining characteristic of RBAC.

Why this answer

Role-based access control assigns permissions to roles and then assigns users to those roles, so access changes automatically when a user's role changes. The hospital's job-title-driven permissions match this model. Discretionary control lets owners set permissions, mandatory control uses labels and clearances, and rule-based control evaluates conditions rather than job functions.

Exam trap

The trap here is confusing role-based access control with rule-based access control because both can be automated, but only RBAC ties permissions to a job function or role.

137
MCQhard

An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?

A.Separation of duties
B.Least privilege
C.Need-to-know
D.Defense in depth
AnswerA

Separation of duties splits a sensitive task across multiple people so no single individual holds end-to-end authority. Requiring a second manager's approval for transactions above $10,000 enforces this by preventing one employee from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.

Why this answer

Requiring two separate approvals for a high-value transaction is the classic definition of separation of duties: no single individual has enough authority to complete a sensitive action alone. This prevents fraud and error by distributing control across multiple people.

Exam trap

CC often tests the overlap between separation of duties and least privilege, so candidates see 'restrict access' language and pick least privilege when the scenario is really about splitting authority across two people.

How to eliminate wrong answers

Option B is wrong because least privilege means granting users only the minimum access needed for their role, not requiring multiple approvers for one action. Option C is wrong because need-to-know restricts access to information based on job relevance, which is about data confidentiality, not transaction authorization. Option D is wrong because defense in depth layers multiple independent controls (firewalls, encryption, MFA) to protect an asset, whereas this scenario is a single dual-approval control.

138
MCQmedium

According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?

A.Requiring a mix of uppercase, lowercase, numbers, and special characters
B.Using randomly generated passwords
C.Changing passwords every 30 days
D.Enforcing a minimum length of at least 8 characters
AnswerD

NIST SP 800-63 prioritises length as the primary strength factor, since each added character multiplies guessing resistance far more than complexity rules. An 8-character minimum satisfies this by raising the search space, though verifiers should also screen against breached-password lists and rate-limit failed attempts.

Why this answer

NIST SP 800-63B explicitly recommends enforcing a minimum password length of at least 8 characters (and encourages longer, up to 64) as the primary strength control, while deprecating composition rules and mandatory rotation. Length is the dominant factor in resisting brute-force and dictionary attacks because it exponentially increases the search space. The guidance prioritizes memorized secrets that are long and unique over complex-but-short passwords.

Exam trap

The trap is that candidates apply legacy password-policy intuition (complexity + rotation = secure) instead of the modern NIST guidance, which inverts those assumptions and elevates length as the primary control.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-63B explicitly advises against requiring composition rules (uppercase, lowercase, numbers, special characters) since they encourage predictable patterns like 'Password1!' and reduce usability without meaningfully improving entropy. Option B is wrong because while randomly generated passwords are strong, NIST guidance focuses on requirements that verifiers should enforce — random generation is a recommendation for password managers, not the primary requirement factor. Option C is wrong because NIST recommends against forced periodic rotation, which leads to predictable incremental changes (e.g., Password1 → Password2) and weakens security; rotation should only occur on evidence of compromise.

139
MCQhard

A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?

A.Logical access control
B.Compensating control
C.Physical access control
D.Administrative control
AnswerA

Account lockout after repeated failed logins is a logical access control: a software-enforced restriction on authentication attempts. It mitigates brute-force or password-guessing attacks from a single source by temporarily denying access, unlike physical or administrative controls.

Why this answer

Account lockout after repeated failed logins is enforced by software (the operating system or application authentication logic), making it a logical access control. Logical controls govern access to systems and data through technical means such as passwords, lockout policies, and permissions, as opposed to physical or administrative controls.

Exam trap

CC often tests the distinction between control types (logical/technical vs. physical vs. administrative) and control functions (preventive vs. compensating), tricking candidates who focus on the attack rather than the control category.

How to eliminate wrong answers

Option B is wrong because a compensating control is an alternative safeguard used when a primary control cannot be implemented (e.g., compensating for missing encryption with network segmentation) — lockout is a primary preventive control, not a substitute. Option C is wrong because physical access controls involve tangible barriers like locks, badges, and guards, not authentication logic. Option D is wrong because administrative controls are policy, procedure, and training-based (e.g., acceptable use policies), not automated technical enforcement.

140
MCQeasy

A payroll clerk changes roles within the same company, moving from the finance department to the human resources department. The security team discovers months later that the clerk still retains all the finance application permissions from the previous position in addition to the new HR permissions. Which access control weakness does this situation illustrate?

A.A brute-force vulnerability, because the clerk's account retained credentials that could be attacked repeatedly.
B.Privilege creep caused by failing to remove access rights when job responsibilities change.
C.An implicit deny failure, because the access control system did not block the finance permissions by default.
D.A separation of duties conflict, because one person now holds finance and HR access simultaneously.
AnswerB

Privilege creep occurs when a user accumulates access rights over time as roles change and old entitlements are never revoked. The clerk's finance permissions should have been removed when the transfer occurred. The residual rights create unnecessary exposure and violate least privilege, making this the accurate description of the weakness.

Why this answer

When employees change roles, their previous entitlements must be revoked so that access always matches current duties. Retaining finance permissions after moving to HR creates privilege creep, a gradual accumulation of rights that violates least privilege and expands the attack surface. Periodic access reviews and prompt deprovisioning during transfers are the standard controls that prevent this situation.

Exam trap

The trap here is confusing accumulated stale permissions with a deliberately designed separation of duties control.

141
MCQmedium

An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?

A.OU=Sales
B.DC=com
C.CN=John Smith
D.DC=company
AnswerA

OU=Sales identifies the organizational unit, since the OU attribute type in a distinguished name denotes a container within the directory hierarchy. The stem asks specifically which component represents the organizational unit, and this value directly satisfies that constraint, distinguishing it from CN (common name) and DC (domain component) elements.

Why this answer

In an LDAP distinguished name (DN), each component is identified by its attribute type. The organizational unit (OU) is represented by the 'OU=' attribute. In the given DN, 'OU=Sales' explicitly designates the organizational unit named 'Sales'.

Exam trap

The trap here is confusing domain components (DC) with organizational units (OU). Candidates might incorrectly select DC=company as the OU because it sounds like an organizational name, but DC always denotes a domain component, not an OU.

How to eliminate wrong answers

Option B is wrong because 'DC=com' represents a domain component, not an organizational unit. Option C is wrong because 'CN=John Smith' represents a common name, typically a user or object. Option D is wrong because 'DC=company' also represents a domain component, not an organizational unit.

142
MCQmedium

A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?

A.The entire sequence is authorization, because the workstation validates a digital certificate.
B.The username provides identification, while the smart card and password together provide authentication.
C.The smart card performs identification, while the username and password perform authentication.
D.The smart card and password together perform identification, while the username performs authentication.
AnswerB

The user states who they claim to be by entering a username, which is identification. The system then verifies that claim through the smart card (something you have) and the password (something you know), which constitute authentication. This two-factor validation matches the classic definition of authentication as proving a claimed identity before authorization is evaluated.

Why this answer

Identification is the act of claiming an identity, and authentication is the act of proving that claim. Typing a username claims an identity, while the smart card and password independently verify it using possession and knowledge factors. Because two distinct factor types are required, the workflow is multi-factor authentication, and authorization would only follow once verification succeeds.

Exam trap

The trap here is assuming that any second credential automatically becomes the identification step rather than remaining part of authentication.

143
Multi-Selecthard

A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)

Select 2 answers
A.Authorization determines what an authenticated cashier is permitted to do within the point-of-sale application.
B.Authentication alone ensures that a cashier cannot perform unauthorized transactions.
C.Least privilege supports limiting each cashier to only the point-of-sale functions required for the assigned duties.
D.Access control decisions should be based solely on the cashier's password complexity.
E.Role-based access control requires each cashier to be assigned permissions individually rather than through a shared role.
AnswersA, C

Authorization occurs after authentication and defines the resources and actions available to an identity. Restricting voids above a threshold and limiting inventory adjustments are authorization decisions applied to an authenticated cashier. This statement correctly describes authorization as the mechanism enforcing these granular permissions in the point-of-sale design.

Why this answer

Authorization defines what an authenticated identity may do, and least privilege limits that access to what the job requires. Together they support the proposed point-of-sale restrictions on voids and inventory adjustments. Authentication merely establishes identity, while role-based access control assigns permissions through roles rather than individual assignments, and password complexity addresses authentication strength only.

Exam trap

The trap here is conflating authentication with authorization, assuming that a verified login automatically prevents actions the user should not perform.

144
Multi-Selecthard

An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?

Select 3 answers
A.Cable locks on laptop computers
B.Password complexity requirements
C.Visitor sign-in log
D.Biometric reader at the server room door
E.Fencing and bollards around the building
AnswersA, D, E

Cable locks physically tether laptops to a fixed anchor, preventing opportunistic theft of endpoint devices. This satisfies the layered strategy by extending physical protection beyond the data centre perimeter to the assets themselves, complementing door, fence and bollard controls.

Why this answer

Option A (cable locks on laptop computers) is correct because a cable lock is a physical deterrent that secures a portable asset to a fixed object, adding a layer of physical defense against theft. Option D (biometric reader at the server room door) is correct because it is a physical access control that authenticates identity via a biological characteristic before granting entry to a restricted area. Option E (fencing and bollards around the building) is correct because perimeter barriers such as fences and bollards are classic physical controls that deter, delay, and prevent unauthorized access or vehicle-borne threats.

Option B (password complexity requirements) is not a physical control but a logical/administrative authentication control, and Option C (visitor sign-in log) is an administrative control that records entry rather than physically preventing or deterring access.

Exam trap

The trap here is confusing logical/administrative controls (like passwords and logs) with physical controls; candidates often select password complexity because it sounds like security, but it does not address physical access.

145
Multi-Selectmedium

A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?

Select 2 answers
A.Requiring password changes every 90 days
B.Account lockout threshold (e.g., 5 failed attempts)
C.Lockout duration (e.g., 30 minutes) or administrator unlock
D.Password history of 10 remembered passwords
E.Password minimum length of 8 characters
AnswersB, C

The lockout threshold defines how many consecutive failed authentication attempts trigger the lockout, directly throttling brute-force guessing. Setting it low, such as five, limits an attacker's attempts per account before the account is disabled, satisfying the requirement to mitigate brute-force attacks.

Why this answer

Option B, the account lockout threshold (e.g., 5 failed attempts), is correct because it directly limits how many incorrect password guesses an attacker can make before the account is disabled, which is the core mechanism that stops brute-force attempts. Option C, lockout duration (e.g., 30 minutes) or administrator unlock, is correct because it determines how long the account stays locked; without a duration or manual unlock requirement, the lockout either never ends or can be trivially bypassed, so it works together with the threshold to make brute-forcing impractical. The unmarked options do not belong because A (90-day password changes), D (password history of 10), and E (minimum length of 8) are password policy settings that improve password strength and prevent reuse, but they do not detect or block repeated failed authentication attempts, which is what account lockout specifically addresses.

Exam trap

The trap is selecting password policy settings (length, history, expiration) as critical for lockout, when the question specifically asks about lockout policies to mitigate brute-force attacks.

146
MCQmedium

A retail chain wants store managers to approve refunds above $500, but the managers should not be able to approve their own refund transactions. The security team must enforce this separation in the point-of-sale system. Which access control model best fits this requirement?

A.Separation of duties enforced through constrained RBAC
B.Rule-based access control
C.Mandatory access control (MAC)
D.Role-based access control (RBAC)
AnswerA

Separation of duties splits sensitive tasks among different people, and constrained RBAC enforces it by defining mutually exclusive roles so one account cannot hold both the initiating and approving permissions. This directly prevents a manager from approving their own refund while still allowing them to approve transactions created by others.

Why this answer

The requirement is that one person must not both create and approve a refund, which is the principle of separation of duties. Constrained RBAC enforces it by making the refund initiation and refund approval roles mutually exclusive, so no single account can hold both. Label-based, role-only, and global rule models cannot express that interpersonal conflict.

Exam trap

The trap here is choosing role-based access control alone, when plain RBAC grants permissions by role without preventing one person from holding conflicting roles.

← PreviousPage 2 of 2 · 146 questions total

Ready to test yourself?

Try a timed practice session using only Access Controls Concepts questions.