easyMultiple Choice
Understanding the Principles of Least Privilege
A security analyst is reviewing the access control policy and notices that some users have been granted 'write' access to a directory that contains sensitive financial reports. Which principle of information security is being violated?
⚠ Common exam trap
It's easy for candidates to confuse the violation of least privilege with a breach of confidentiality, but the question specifically highlights the granting of unnecessary write permissions, which is a direct violation of the least privilege principle, not merely a confidentiality issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. Granting 'write' access to a directory containing sensitive financial reports to users who do not require that level of access violates this principle, as it introduces unnecessary risk of unauthorized modification or data leakage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation proves a specific party performed an action, typically via digital signatures or audit logging; excessive write access does not undermine that proof. It would be the answer if users could deny having modified or sent the financial reports.
- ✓
Least privilege
Why this is correct
Granting write access to sensitive financial reports exceeds what users need to perform their duties, breaching least privilege — the principle that subjects receive only the minimum access rights required. The stem's constraint is unnecessary write permission on a sensitive directory, which least privilege directly prohibits.
- ✗
Availability
Why it's wrong here
Availability concerns uptime and reachability of data, whereas write access to financial reports threatens their accuracy, which is integrity. Availability would be the correct principle if the reports were inaccessible due to outages, denial-of-service or resource exhaustion.
- ✗
Confidentiality
Why it's wrong here
Granting write access to sensitive financial reports lets users alter or delete them, breaching integrity, not confidentiality. Confidentiality concerns unauthorised read access, so it would be the answer if users could merely view the reports without a need to know.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.