SSCP Access Controls Practice Question
What is the primary risk associated with service accounts in an enterprise?
⚠ Common exam trap
SSCP often tests the misconception that service accounts are secure because they are not used by humans, but the real risk is their excessive privileges and static credentials, which candidates may overlook in favor of less critical issues like shared use or difficulty of creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They often have excessive privileges and infrequent password changes
Service accounts are non-human accounts used by applications, daemons, or scheduled tasks to run processes and access resources. Because they must operate without interactive logon, they are frequently granted broad privileges (e.g., domain admin, local system) to ensure the service functions correctly. Additionally, their passwords are often set once and never rotated, or are hard-coded in scripts, making them a prime target for credential theft and lateral movement. Thus, the primary risk is the combination of excessive privileges and infrequent password changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are used by multiple users simultaneously
Why it's wrong here
Shared simultaneous use is a symptom of poor credential hygiene, not the inherent risk. Service accounts are non-human identities whose credentials are long-lived and often over-privileged; that persistence and privilege breadth is the primary exposure, regardless of how many users invoke them.
- ✗
They are difficult to create
Why it's wrong here
Creating a service account is straightforward in Microsoft Entra ID, Active Directory or any directory service, so difficulty is not the risk. It is tempting because provisioning friction can cause shadow accounts, but the genuine risk is credential sprawl and lack of rotation, not the creation process itself.
- ✓
They often have excessive privileges and infrequent password changes
Why this is correct
Service accounts typically hold broad, long-lived credentials because they run automated processes, and their passwords are rarely rotated. This combination satisfies the stem's constraint: excessive privileges paired with infrequent password changes creates a prime target for lateral movement and credential abuse.
- ✗
They are always tied to a specific user
Why it's wrong here
Service accounts are deliberately not tied to a person; they are owned by a workload or application. It is tempting because personal ownership sounds like accountability, but the real risk is the opposite: orphaned accounts with no identifiable owner, whose credentials persist unrotated after staff or projects depart.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?
medium- A.Need-to-know
- B.Separation of duties
- ✓ C.Least privilege
- D.Accountability
Why C: Granting a service account domain administrator privileges violates the principle of least privilege, which states that accounts should have only the minimum permissions necessary to perform their required tasks. A service account typically needs limited, specific permissions, not full domain admin rights. This over-provisioning increases the attack surface and risk.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.