Courseiva
easyMultiple Select

CISSP Practice Question: Which TWO principles are essential for…

Which TWO principles are essential for implementing least privilege in identity and access management?

⚠ Common exam trap

Candidates often confuse 'least privilege' (which limits system permissions and rights) with 'need-to-know' (which limits access to specific data/information). While they are distinct concepts, they are both essential, complementary principles used together to enforce secure access control in IAM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Minimum necessary permissions

Minimum necessary permissions (A) is a core least-privilege principle: identities should be granted only the specific permissions required to perform their job function, and no broader access, so the potential blast radius of a compromised or misused account is minimized. Need-to-know (B) is the complementary principle that access to information or resources should be granted only when a user has a legitimate, job-related requirement to know or use that data, which directly limits unnecessary exposure. Together, A and B define least privilege by restricting both the scope of permissions and the justification for accessing resources. Segregation of duties (C) is a fraud- and error-prevention control that splits critical tasks among different people, but it is not itself a least-privilege principle. User awareness training (D) and password complexity requirements (E) are supporting security controls that improve human behavior and credential strength, but they do not define or implement least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Minimum necessary permissions

    Why this is correct

    Minimum necessary permissions is the direct operationalization of least privilege, dictating that users, applications, or systems should be granted only the exact access rights and privileges required to perform their legitimate functions. This principle significantly reduces the attack surface and limits the potential scope of damage if an account or system is compromised, preventing the granting of excessive or unnecessary access by default.

  • ✓

    Need-to-know

    Why this is correct

    Need-to-know is a fundamental information security principle that works in conjunction with least privilege, specifically concerning data access. It mandates that individuals should only be granted access to information or resources that are absolutely essential for them to perform their assigned job duties and nothing more. This ensures sensitive data is not exposed unnecessarily and reinforces the concept of restricting access to the bare minimum required.

  • ✗

    Segregation of duties

    Why it's wrong here

    Segregation of duties (SoD) is a critical internal control designed to prevent fraud, error, and abuse by ensuring that no single individual can complete a critical task alone. While it involves distributing responsibilities and implicitly limiting individual capabilities, its primary goal is to prevent conflicts of interest or malicious acts by requiring multiple parties, rather than solely restricting permissions to the minimum necessary for a single role.

  • ✗

    User awareness training

    Why it's wrong here

    User awareness training is a crucial component of an organization's overall security posture, focused on educating employees about security policies, threats, and best practices to reduce human error. While it indirectly supports security by fostering a security-conscious culture and improving compliance, it is a preventative measure focused on user behavior and knowledge, not a direct principle governing the assignment of access rights or authorization levels.

  • ✗

    Password complexity requirements

    Why it's wrong here

    Password complexity requirements are an authentication control designed to strengthen user identity verification by making passwords harder to guess or crack through brute-force attacks. This control ensures that only legitimate users can prove their identity to a system. However, it does not dictate what resources those authenticated users can access; least privilege, conversely, is an authorization principle that governs *what* an authenticated user or process is permitted to do.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.