ISC2 CC Access Controls Concepts Practice Question
Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?
⚠ Common exam trap
The trap is overthinking 'service account' as the highest risk — while service accounts are risky, the exam expects admin/root as the top-tier account requiring separate daily-use accounts and strict controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Admin/root account
Admin/root accounts have unrestricted privileges over systems, data, and configurations, making them the highest-value target for attackers — compromise grants full control. Best practice is to protect them with strict controls (MFA, privileged access workstations, just-in-time elevation) and use separate, non-privileged accounts for daily tasks like email and browsing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Standard user account
Why it's wrong here
Standard user accounts hold limited rights and are the baseline for daily work, so they are not the highest-risk type. Privileged accounts, such as domain administrators, carry elevated rights and are the accounts requiring separate daily-use identities and strict controls.
- ✗
Service account
Why it's wrong here
Service accounts are non-interactive and typically lack separate daily-use credentials, so they are not the highest-risk type requiring that control. They are tempting because they often hold elevated privileges and are prime targets, making them the correct answer when the question asks which accounts should have interactive logon disabled and managed secrets.
- ✓
Admin/root account
Why this is correct
Admin and root accounts hold unrestricted control over systems and data, so their compromise yields immediate full impact. Separate daily-use accounts ensure routine browsing and email never expose these credentials, satisfying the strict-control requirement for the highest-risk account type.
- ✗
Guest account
Why it's wrong here
Guest accounts are external, low-privilege and time-limited, so they do not demand separate daily-use accounts. They are tempting because they represent untrusted access, making them the right answer when the question asks which account type poses external risk and should be reviewed for stale or unnecessary access.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.