hardMultiple Select
ISC2 CC Practice Question: Which TWO of the following are examples of…
Which TWO of the following are examples of implementing the principle of least privilege?
⚠ Common exam trap
CC often tests the difference between least privilege and other security principles like defense in depth or authentication — candidates may select two-factor authentication or firewalls as least privilege, but those are separate controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assigning a database administrator only the permissions required for their specific tasks
Option B is correct because least privilege means granting an identity only the minimum access rights needed to perform its job function; giving a database administrator just the permissions required for their specific tasks directly enforces that restriction. Option E is correct because granting a user read-only access to a file they only need to view limits them to the least access necessary (read) rather than granting write or modify rights. Option A is not least privilege because a security camera is a physical monitoring control, not an access-rights restriction. Option C is not least privilege because two-factor authentication strengthens authentication assurance but does not limit the permissions an administrator holds. Option D is not least privilege because a firewall filtering inbound traffic to port 443 is a network access control, not the assignment of minimal permissions to a user or role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Installing a security camera at the data center entrance
Why it's wrong here
A security camera is a physical detective control that records activity; it neither grants nor restricts any permission, so least privilege is untouched. It is tempting because it is a genuine security measure, but least privilege concerns minimising assigned rights; cameras would be correct when the requirement is monitoring or deterrence.
- ✓
Assigning a database administrator only the permissions required for their specific tasks
Why this is correct
Granting the database administrator only the permissions their specific tasks demand directly enacts least privilege, which requires limiting each identity to the minimum access necessary. This satisfies the stem's constraint by scoping rights to job function rather than granting broad, standing database privileges, thereby reducing the blast radius of compromised or misused credentials.
- ✗
Requiring two-factor authentication for system administrators
Why it's wrong here
Two-factor authentication strengthens authentication assurance but grants no reduction in permissions, so it does not implement least privilege. It is tempting because it is a recognised access-control safeguard, yet least privilege concerns limiting rights to the minimum required; MFA would be the correct control when the requirement is verifying identity strength.
- ✗
Implementing a firewall to block all incoming traffic except on port 443
Why it's wrong here
A firewall filtering inbound traffic is a network perimeter control, not an assignment of minimal permissions to identities. It is tempting because restricting ports resembles limiting access, but least privilege governs which rights users and services hold; a firewall would be correct when the requirement is reducing exposed network attack surface.
- ✓
Granting a user read-only access to a file they need to view
Why this is correct
Granting read-only access delivers exactly the permissions required to view the file and nothing more, satisfying least privilege by eliminating write, delete and modify rights the user does not need. This limits potential damage from accidental edits or compromised credentials, since the account cannot alter the resource.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are examples of the principle of least privilege? (Select THREE.)
medium- ✓ A.Granting a user only the permissions needed to perform their job
- B.Giving all employees full access to the file server
- ✓ C.Allowing a contractor access only during their contract period
- ✓ D.Providing read-only access to a database for a reporting analyst
- E.Assigning administrator rights to all employees by default
Why A: Option A is correct because least privilege means granting a user only the specific permissions required to perform their job functions, nothing more. Option C is correct because limiting a contractor's access to the duration of their contract enforces least privilege by ensuring access is revoked when no longer needed (time-bound access). Option D is correct because giving a reporting analyst read-only access to a database restricts them to the minimum access necessary for reporting, preventing unnecessary write or administrative capabilities. Options B and E are incorrect because granting all employees full file server access or administrator rights by default violates least privilege by providing excessive, broad permissions beyond what any individual role requires.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.