Courseiva

CISSP Security Architecture and Engineering Practice Question

A security architect is designing a system that must enforce the principle of least privilege for a set of applications. The applications need to access a shared database, but each application should only have the minimum permissions necessary to perform its function. The architect decides to implement a mechanism where each application runs with its own set of credentials and permissions, and these permissions are checked at every access attempt. Which security principle is best demonstrated by this design?

⚠ Common exam trap

Watch out — candidates often confuse least privilege with implicit deny, because both involve restricting access, but least privilege is about granting minimal necessary permissions, while implicit deny is about denying by default unless explicitly allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

The design gives each application its own credentials and permissions and checks them at every access, ensuring that each application has only the minimum access required. This is the definition of least privilege. Separation of duties, defense in depth, and implicit deny are related security principles but do not capture the specific requirement of minimizing permissions for each application to only what is necessary for its function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Least privilege

    Why this is correct

    Least privilege requires that each subject (in this case, each application) be granted only the minimum permissions necessary to perform its function. By giving each application its own credentials and permissions and checking them at every access, the architect ensures that no application has more access than it needs. This directly implements the principle of least privilege, reducing the risk of unauthorized access or damage if an application is compromised.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties divides critical tasks among multiple individuals to prevent fraud or errors. In this scenario, the focus is on limiting each application's permissions to the minimum required, not on dividing tasks among different entities. While separation of duties is a valuable control, it does not directly address the need for each application to have only the permissions necessary for its function, which is the core of least privilege.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth involves layering multiple security controls so that if one fails, others still protect the system. While the described design adds a layer of access control, the primary goal is to limit permissions per application, not to create multiple independent layers. The scenario does not mention additional layers such as network segmentation, encryption, or monitoring, so defense in depth is not the best description of the core principle being applied.

  • ✗

    Implicit deny

    Why it's wrong here

    Implicit deny means that unless a subject is explicitly granted access, access is denied by default. This is a fundamental access control principle, but the scenario focuses on granting each application only the permissions it needs, which is least privilege. Implicit deny is about the default stance, whereas least privilege is about minimizing the permissions granted. The design described emphasizes the latter, not the default denial of unlisted access.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.