Courseiva
Access Controls →hardMultiple Select

SSCP Access Controls Practice Question

An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)

⚠ Common exam trap

SSCP often tests whether candidates can distinguish fundamental access control principles (least privilege, need-to-know, separation of duties) from broader security strategies (defense in depth) or insecure failure modes (fail-open).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

Option B (Least privilege) is correct because users and processes should be granted only the minimum access rights necessary to perform their assigned tasks, reducing the attack surface and limiting damage from compromised accounts. Option C (Need-to-know) is correct because access to specific information should be restricted to individuals who require it to fulfill their job responsibilities, which is a foundational access control principle closely tied to least privilege. Option D (Separation of duties) is correct because splitting critical tasks among multiple users prevents any single person from having enough control to commit fraud or cause significant harm without detection, a core principle in access control policy design. Option A (Fail-open) is not a fundamental access control principle; fail-open means a system defaults to allowing access when it fails, which is generally a security weakness rather than a policy principle. Option E (Defense in depth) is a valid security architecture concept involving layered controls, but it is not one of the three fundamental access control principles being asked for here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fail-open

    Why it's wrong here

    Fail-open grants access when a control fails, directly violating the access control principle of fail-safe defaults, which requires denying access on failure. It is tempting because availability-focused systems sometimes adopt it deliberately. Fail-open would be the correct design choice only where denying access causes greater harm than permitting it, such as certain life-safety systems.

  • ✓

    Least privilege

    Why this is correct

    Least privilege grants each user only the minimum access rights required to perform their role, reducing the blast radius of compromised accounts or insider misuse. It is fundamental because the access control policy must limit permissions by default rather than granting broad standing access.

  • ✓

    Need-to-know

    Why this is correct

    Need-to-know restricts access to information strictly required for a user's specific task, independent of their rank or clearance. It is fundamental because the policy must ensure sensitive data is disclosed only to those with a legitimate, current requirement.

  • ✓

    Separation of duties

    Why this is correct

    Separation of duties splits critical tasks across different individuals so no single person controls an entire privileged process, preventing fraud and accidental misuse. It is a fundamental access control principle because it enforces checks and balances within the new system's authorisation design.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth is a security architecture strategy layering multiple controls, not an access control policy principle. The stem asks for access control fundamentals such as least privilege, separation of duties and need to know, which govern how permissions are assigned. Defense in depth would be correct when designing overall security architecture across network, host and application tiers.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.