CISSP Identity and Access Management Practice Question
Which principle ensures that a user is granted only the permissions necessary to perform their job functions?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
The principle of least privilege states that users should have the minimum level of access required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Need-to-know
Why it's wrong here
The 'need-to-know' principle dictates that access to specific information or data is granted only when an individual's job function absolutely requires it for their duties. It primarily focuses on restricting access to sensitive information to maintain confidentiality and prevent unauthorized disclosure, rather than governing the scope of operational permissions or system capabilities a user can execute. While related to access control, it is distinct from limiting the actual privileges to perform actions.
- ✓
Least privilege
Why this is correct
The principle of least privilege mandates that users, programs, or processes are granted only the absolute minimum set of permissions or access rights required to perform their legitimate tasks and nothing more. This fundamental security practice minimizes the attack surface by reducing the potential damage from accidental errors, insider threats, or successful external attacks, as compromised accounts have severely limited capabilities. It directly ensures a user is granted only the necessary permissions.
- ✗
Separation of duties
Why it's wrong here
Separation of duties (SoD) is a control mechanism designed to prevent fraud, error, and abuse by requiring that no single individual has complete control over a critical or sensitive process from start to finish. It divides tasks that, if combined, could lead to a conflict of interest or potential compromise, among multiple individuals. This principle focuses on process integrity and accountability across multiple roles, not on the granular permissions granted to a single user.
- ✗
Zero standing privileges
Why it's wrong here
Zero standing privileges (ZSP) is an advanced security concept where no user or system account possesses permanent administrative or elevated access rights. Instead, privileges are granted just-in-time (JIT) and for a limited duration only when explicitly requested, approved, and needed for a specific task. While ZSP is a highly effective method for managing and reducing the risk associated with privileged accounts, it is a *strategy* for implementing privilege management, not the fundamental *principle* that ensures a user is granted *only* the necessary permissions in the first place.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.