mediumMultiple SelectObjective-mapped
ISC2 CC Practice Question: Which TWO scenarios best illustrate the principle…
Which TWO scenarios best illustrate the principle of least privilege?
⚠ Common exam trap
ISC2 often tests the misconception that 'least privilege' means giving users the minimum permissions to do their job, but candidates may confuse it with 'separation of duties' or think that granting root access to executives is acceptable because they are trusted, which is a trap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An administrator uses a separate standard account for daily work and an admin account only when needed
It demonstrates the principle of least privilege by using a separate standard user account for daily tasks and elevating to an administrative account only when necessary. This minimizes the attack surface by ensuring that administrative privileges are not active during routine activities, reducing the risk of accidental system changes or malware execution with elevated rights. In Windows environments, this is commonly implemented via User Account Control (UAC) and the use of a standard vs. administrator account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Regular employees can install software on their workstations
Why it's wrong here
Installation rights often exceed job needs.
- ✗
The CEO has root access to all servers
Why it's wrong here
Root access is excessive unless required.
- ✓
An administrator uses a separate standard account for daily work and an admin account only when needed
Why this is correct
Running with minimal privileges reduces risk.
- ✗
All users have full control over shared folders
Why it's wrong here
Full control violates least privilege.
- ✓
A user has only the permissions required to perform their job
Why this is correct
Core definition of least privilege.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
UAC
User Account Control is a Windows security feature that prevents unauthorized changes to your computer by asking for permission before allowing certain actions.
About these practice questions
One of 976 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.