ISC2 CC Access Controls Concepts Practice Question
Which access control principle restricts access to data based on the user's job role and tasks?
⚠ Common exam trap
The trap is conflating least privilege with need to know — CC frequently presents scenarios where the user has the minimum permission level but still sees data they shouldn't, which is a need-to-know violation, not least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Need to know
Need to know restricts access based on the specific data a user requires to perform their job tasks, which is exactly what the question describes. It is narrower than least privilege: least privilege limits the level of access (e.g., read vs. write), while need to know limits which specific data the user can see.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of duties
Why it's wrong here
Separation of duties divides a critical process among multiple people to prevent fraud, rather than granting access according to job role. It is tempting because both are access control principles, but role-based access control is the mechanism that maps permissions to a user's job function and tasks.
- ✓
Need to know
Why this is correct
Need to know restricts data access to what a user's role and tasks actually require, rather than granting broad access by seniority or department. This matches the stem's requirement to limit access based on job role and duties.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls so failure of one does not expose the asset; it does not map permissions to job roles. It is tempting because layered controls often accompany role-based access, but the principle restricting data by role and task is role-based access control.
- ✗
Least privilege
Why it's wrong here
Least privilege grants only the minimum rights needed for a specific task, not the full set of permissions a job role requires. It is tempting because both limit access, but least privilege is per-task and time-bound, whereas role-based access control assigns permissions by job function.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Need to know
Need to know is a security principle that restricts access to information or resources only to individuals who require that access to perform their job duties.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.