hardMultiple Select
ISC2 CC Practice Question: Which TWO of the following are best practices for…
Which TWO of the following are best practices for implementing the principle of least privilege?
⚠ Common exam trap
The trap is that removing default accounts sounds like least privilege, but it is account hardening; candidates must focus on the two options that actually scope and review user permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign permissions based on the minimum necessary to perform job functions
Option B is correct because least privilege means granting each user only the access rights required to perform their specific job functions, nothing more, which directly limits the blast radius of compromised or misused accounts. Option E is correct because least privilege is not a one-time configuration; permissions tend to accumulate through role changes and project work, so periodic access reviews and revocation of unnecessary privileges keep entitlements aligned with current job duties. Option A is wrong because granting full administrative rights to all users is the opposite of least privilege and dramatically increases risk. Option C is wrong because a single shared administrative account destroys individual accountability and prevents per-user privilege scoping. Option D is wrong because removing all default accounts is not a least-privilege practice; some default accounts may be required, and the proper approach is to rename, disable, or restrict them as appropriate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant all users full administrative rights to reduce support calls
Why it's wrong here
Granting every user full administrative rights directly violates least privilege, which requires each identity to hold only the permissions its role needs. It is tempting because it eliminates permission-related support tickets, but it maximises blast radius from compromised accounts. Role-based scoped access with just-in-time elevation is the correct approach.
- ✓
Assign permissions based on the minimum necessary to perform job functions
Why this is correct
Least privilege means granting only the access required for a user's job function, nothing broader. This directly limits the blast radius of compromised accounts and satisfies the principle's core constraint: permissions scoped to actual duties rather than convenience or role seniority.
- ✗
Use a single shared administrative account for all IT staff
Why it's wrong here
A shared administrative account destroys individual accountability, prevents attribution in audit logs, and cannot be scoped per person, contradicting least privilege. It is tempting because it simplifies credential management for IT teams. The correct approach gives each administrator a named account with only the privileges their duties require.
- ✗
Remove all default accounts from systems
Why it's wrong here
Removing default accounts outright can break services and applications that depend on them, and least privilege concerns limiting each identity's permissions, not deleting built-in accounts. The practice is tempting because unused defaults are genuine risk; the correct approach is disabling or renaming them and rotating credentials, not blanket removal.
- ✓
Regularly review and revoke unnecessary privileges
Why this is correct
Permissions accumulate as roles change, so periodic access reviews identify and revoke stale or excessive entitlements. This maintains least privilege over time, satisfying the requirement that granted rights stay minimal rather than drifting upward through transfers and project work.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Remote Authentication Dial-in User Service
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting for users trying to connect to a network service.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.