mediumMultiple Select
ISC2 CC Which TWO are principles of access control? Practice Question
Which TWO are principles of access control?
⚠ Common exam trap
ISC2 often tests the distinction between access control principles (like least privilege and separation of duties) and access control mechanisms or technologies (like multifactor authentication and SSO), causing candidates to confuse a method for a principle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
Separation of duties (A) is a fundamental access control principle because it divides critical tasks among multiple people so that no single individual has enough authority to compromise the system, thereby preventing fraud and error. Least privilege (E) is also a core access control principle, requiring that users be granted only the minimum permissions necessary to perform their job functions, which limits the potential damage from accidents or malicious activity. In contrast, security through obscurity (B) is a discouraged practice of relying on secrecy of design rather than sound security controls, not an access control principle. Multifactor authentication (C) and single sign-on (D) are authentication mechanisms or convenience technologies, not foundational access control principles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties
Why this is correct
Separation of duties splits critical tasks across multiple people so no single individual controls an entire process, preventing fraud and error. It is a foundational access control principle governing how permissions are assigned and reviewed, not a technical mechanism or physical control.
- ✗
Security through obscurity
Why it's wrong here
Security through obscurity hides implementation details rather than enforcing authorisation, so it is not an access-control principle like least privilege or need-to-know. It tempts because obscurity can add defence in depth, but access control rests on explicit permission decisions, not on secrecy of design.
- ✗
Multifactor authentication
Why it's wrong here
Multifactor authentication strengthens identity verification at sign-in; it is an authentication control, not an access-control principle such as least privilege or separation of duties. It tempts because MFA is a core security requirement, but it establishes who you are, not what resources you are permitted to reach.
- ✗
Single sign-on (SSO)
Why it's wrong here
SSO is a convenience mechanism, not a principle.
- ✓
Least privilege
Why this is correct
Least privilege grants users only the minimum access needed to perform their duties, limiting potential damage from misuse or compromise. It is a core access control principle guiding permission assignment and review, distinct from authentication mechanisms or physical safeguards.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.