Courseiva
easyMultiple Choice

Understanding the Principles of Least Privilege

A security analyst is reviewing the access control policy and notices that some users have been granted 'write' access to a directory that contains sensitive financial reports. Which principle of information security is being violated?

⚠ Common exam trap

It's easy for candidates to confuse the violation of least privilege with a breach of confidentiality, but the question specifically highlights the granting of unnecessary write permissions, which is a direct violation of the least privilege principle, not merely a confidentiality issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. Granting 'write' access to a directory containing sensitive financial reports to users who do not require that level of access violates this principle, as it introduces unnecessary risk of unauthorized modification or data leakage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation proves a specific party performed an action, typically via digital signatures or audit logging; excessive write access does not undermine that proof. It would be the answer if users could deny having modified or sent the financial reports.

  • ✓

    Least privilege

    Why this is correct

    Granting write access to sensitive financial reports exceeds what users need to perform their duties, breaching least privilege — the principle that subjects receive only the minimum access rights required. The stem's constraint is unnecessary write permission on a sensitive directory, which least privilege directly prohibits.

  • ✗

    Availability

    Why it's wrong here

    Availability concerns uptime and reachability of data, whereas write access to financial reports threatens their accuracy, which is integrity. Availability would be the correct principle if the reports were inaccessible due to outages, denial-of-service or resource exhaustion.

  • ✗

    Confidentiality

    Why it's wrong here

    Granting write access to sensitive financial reports lets users alter or delete them, breaching integrity, not confidentiality. Confidentiality concerns unauthorised read access, so it would be the answer if users could merely view the reports without a need to know.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.