Courseiva
Access Controls Concepts →easyMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

Which access control principle restricts access to data based on the user's job role and tasks?

⚠ Common exam trap

The trap is conflating least privilege with need to know — CC frequently presents scenarios where the user has the minimum permission level but still sees data they shouldn't, which is a need-to-know violation, not least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Need to know

Need to know restricts access based on the specific data a user requires to perform their job tasks, which is exactly what the question describes. It is narrower than least privilege: least privilege limits the level of access (e.g., read vs. write), while need to know limits which specific data the user can see.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties divides a critical process among multiple people to prevent fraud, rather than granting access according to job role. It is tempting because both are access control principles, but role-based access control is the mechanism that maps permissions to a user's job function and tasks.

  • ✓

    Need to know

    Why this is correct

    Need to know restricts data access to what a user's role and tasks actually require, rather than granting broad access by seniority or department. This matches the stem's requirement to limit access based on job role and duties.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple independent controls so failure of one does not expose the asset; it does not map permissions to job roles. It is tempting because layered controls often accompany role-based access, but the principle restricting data by role and task is role-based access control.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege grants only the minimum rights needed for a specific task, not the full set of permissions a job role requires. It is tempting because both limit access, but least privilege is per-task and time-bound, whereas role-based access control assigns permissions by job function.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.