Courseiva
hardMultiple Select

ISC2 CC Practice Question: Which TWO of the following are examples of…

Which TWO of the following are examples of implementing the principle of least privilege?

⚠ Common exam trap

CC often tests the difference between least privilege and other security principles like defense in depth or authentication — candidates may select two-factor authentication or firewalls as least privilege, but those are separate controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assigning a database administrator only the permissions required for their specific tasks

Option B is correct because least privilege means granting an identity only the minimum access rights needed to perform its job function; giving a database administrator just the permissions required for their specific tasks directly enforces that restriction. Option E is correct because granting a user read-only access to a file they only need to view limits them to the least access necessary (read) rather than granting write or modify rights. Option A is not least privilege because a security camera is a physical monitoring control, not an access-rights restriction. Option C is not least privilege because two-factor authentication strengthens authentication assurance but does not limit the permissions an administrator holds. Option D is not least privilege because a firewall filtering inbound traffic to port 443 is a network access control, not the assignment of minimal permissions to a user or role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Installing a security camera at the data center entrance

    Why it's wrong here

    A security camera is a physical detective control that records activity; it neither grants nor restricts any permission, so least privilege is untouched. It is tempting because it is a genuine security measure, but least privilege concerns minimising assigned rights; cameras would be correct when the requirement is monitoring or deterrence.

  • ✓

    Assigning a database administrator only the permissions required for their specific tasks

    Why this is correct

    Granting the database administrator only the permissions their specific tasks demand directly enacts least privilege, which requires limiting each identity to the minimum access necessary. This satisfies the stem's constraint by scoping rights to job function rather than granting broad, standing database privileges, thereby reducing the blast radius of compromised or misused credentials.

  • ✗

    Requiring two-factor authentication for system administrators

    Why it's wrong here

    Two-factor authentication strengthens authentication assurance but grants no reduction in permissions, so it does not implement least privilege. It is tempting because it is a recognised access-control safeguard, yet least privilege concerns limiting rights to the minimum required; MFA would be the correct control when the requirement is verifying identity strength.

  • ✗

    Implementing a firewall to block all incoming traffic except on port 443

    Why it's wrong here

    A firewall filtering inbound traffic is a network perimeter control, not an assignment of minimal permissions to identities. It is tempting because restricting ports resembles limiting access, but least privilege governs which rights users and services hold; a firewall would be correct when the requirement is reducing exposed network attack surface.

  • ✓

    Granting a user read-only access to a file they need to view

    Why this is correct

    Granting read-only access delivers exactly the permissions required to view the file and nothing more, satisfying least privilege by eliminating write, delete and modify rights the user does not need. This limits potential damage from accidental edits or compromised credentials, since the account cannot alter the resource.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE of the following are examples of the principle of least privilege? (Select THREE.)

medium
  • ✓ A.Granting a user only the permissions needed to perform their job
  • B.Giving all employees full access to the file server
  • ✓ C.Allowing a contractor access only during their contract period
  • ✓ D.Providing read-only access to a database for a reporting analyst
  • E.Assigning administrator rights to all employees by default

Why A: Option A is correct because least privilege means granting a user only the specific permissions required to perform their job functions, nothing more. Option C is correct because limiting a contractor's access to the duration of their contract enforces least privilege by ensuring access is revoked when no longer needed (time-bound access). Option D is correct because giving a reporting analyst read-only access to a database restricts them to the minimum access necessary for reporting, preventing unnecessary write or administrative capabilities. Options B and E are incorrect because granting all employees full file server access or administrator rights by default violates least privilege by providing excessive, broad permissions beyond what any individual role requires.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.