Courseiva
mediumMultiple Select

ISC2 CC Which TWO are principles of access control? Practice Question

Which TWO are principles of access control?

⚠ Common exam trap

ISC2 often tests the distinction between access control principles (like least privilege and separation of duties) and access control mechanisms or technologies (like multifactor authentication and SSO), causing candidates to confuse a method for a principle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties

Separation of duties (A) is a fundamental access control principle because it divides critical tasks among multiple people so that no single individual has enough authority to compromise the system, thereby preventing fraud and error. Least privilege (E) is also a core access control principle, requiring that users be granted only the minimum permissions necessary to perform their job functions, which limits the potential damage from accidents or malicious activity. In contrast, security through obscurity (B) is a discouraged practice of relying on secrecy of design rather than sound security controls, not an access control principle. Multifactor authentication (C) and single sign-on (D) are authentication mechanisms or convenience technologies, not foundational access control principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Separation of duties

    Why this is correct

    Separation of duties splits critical tasks across multiple people so no single individual controls an entire process, preventing fraud and error. It is a foundational access control principle governing how permissions are assigned and reviewed, not a technical mechanism or physical control.

  • ✗

    Security through obscurity

    Why it's wrong here

    Security through obscurity hides implementation details rather than enforcing authorisation, so it is not an access-control principle like least privilege or need-to-know. It tempts because obscurity can add defence in depth, but access control rests on explicit permission decisions, not on secrecy of design.

  • ✗

    Multifactor authentication

    Why it's wrong here

    Multifactor authentication strengthens identity verification at sign-in; it is an authentication control, not an access-control principle such as least privilege or separation of duties. It tempts because MFA is a core security requirement, but it establishes who you are, not what resources you are permitted to reach.

  • ✗

    Single sign-on (SSO)

    Why it's wrong here

    SSO is a convenience mechanism, not a principle.

  • ✓

    Least privilege

    Why this is correct

    Least privilege grants users only the minimum access needed to perform their duties, limiting potential damage from misuse or compromise. It is a core access control principle guiding permission assignment and review, distinct from authentication mechanisms or physical safeguards.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.