easyMultiple Select
CISSP Practice Question: Which TWO principles are essential for…
Which TWO principles are essential for implementing least privilege in identity and access management?
⚠ Common exam trap
Candidates often confuse 'least privilege' (which limits system permissions and rights) with 'need-to-know' (which limits access to specific data/information). While they are distinct concepts, they are both essential, complementary principles used together to enforce secure access control in IAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Minimum necessary permissions
Minimum necessary permissions (A) is a core least-privilege principle: identities should be granted only the specific permissions required to perform their job function, and no broader access, so the potential blast radius of a compromised or misused account is minimized. Need-to-know (B) is the complementary principle that access to information or resources should be granted only when a user has a legitimate, job-related requirement to know or use that data, which directly limits unnecessary exposure. Together, A and B define least privilege by restricting both the scope of permissions and the justification for accessing resources. Segregation of duties (C) is a fraud- and error-prevention control that splits critical tasks among different people, but it is not itself a least-privilege principle. User awareness training (D) and password complexity requirements (E) are supporting security controls that improve human behavior and credential strength, but they do not define or implement least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Minimum necessary permissions
Why this is correct
Minimum necessary permissions is the direct operationalization of least privilege, dictating that users, applications, or systems should be granted only the exact access rights and privileges required to perform their legitimate functions. This principle significantly reduces the attack surface and limits the potential scope of damage if an account or system is compromised, preventing the granting of excessive or unnecessary access by default.
- ✓
Need-to-know
Why this is correct
Need-to-know is a fundamental information security principle that works in conjunction with least privilege, specifically concerning data access. It mandates that individuals should only be granted access to information or resources that are absolutely essential for them to perform their assigned job duties and nothing more. This ensures sensitive data is not exposed unnecessarily and reinforces the concept of restricting access to the bare minimum required.
- ✗
Segregation of duties
Why it's wrong here
Segregation of duties (SoD) is a critical internal control designed to prevent fraud, error, and abuse by ensuring that no single individual can complete a critical task alone. While it involves distributing responsibilities and implicitly limiting individual capabilities, its primary goal is to prevent conflicts of interest or malicious acts by requiring multiple parties, rather than solely restricting permissions to the minimum necessary for a single role.
- ✗
User awareness training
Why it's wrong here
User awareness training is a crucial component of an organization's overall security posture, focused on educating employees about security policies, threats, and best practices to reduce human error. While it indirectly supports security by fostering a security-conscious culture and improving compliance, it is a preventative measure focused on user behavior and knowledge, not a direct principle governing the assignment of access rights or authorization levels.
- ✗
Password complexity requirements
Why it's wrong here
Password complexity requirements are an authentication control designed to strengthen user identity verification by making passwords harder to guess or crack through brute-force attacks. This control ensures that only legitimate users can prove their identity to a system. However, it does not dictate what resources those authenticated users can access; least privilege, conversely, is an authorization principle that governs *what* an authenticated user or process is permitted to do.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Access token
A digital key that a computer system gives you to prove your identity and grant you permission to access specific resources or perform actions.
Key term
RADIUS
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.