Courseiva

Least Privilege Principle

A security administrator is configuring permissions for a new cloud-based expense reporting application. The administrator assigns each employee only the permissions they need to perform their job functions. For example, employees in the Sales department can view expense reports but cannot approve or modify financial data. Which security principle is the administrator implementing?

Quick Answer

The correct answer is the principle of least privilege. This security concept dictates that users should be granted only the minimum permissions necessary to complete their job tasks, as demonstrated when Sales employees can view expense reports but cannot approve or modify financial data. By restricting access in this way, the attack surface is reduced, and the potential damage from a compromised account is contained. On the Microsoft SC-900 exam, this principle frequently appears in scenarios involving role-based access control (RBAC) in cloud applications like expense reporting or HR systems, often testing your ability to distinguish it from concepts like separation of duties or need-to-know. A common trap is confusing least privilege with zero trust—remember, least privilege is about limiting permissions, while zero trust is a broader security model. Memory tip: think “just enough access, just in time.”

⚠ Common exam trap

Watch out — candidates often confuse least privilege with separation of duties, because both involve restricting access, but separation of duties specifically requires splitting conflicting tasks (e.g., submit vs. approve) across different users to prevent fraud, whereas least privilege focuses on minimizing permissions per user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Least privilege

The administrator is granting each employee only the permissions necessary to perform their job functions, such as Sales being able to view but not approve or modify financial data. This directly implements the principle of least privilege, which restricts access rights to the minimum required for legitimate tasks. In cloud-based applications like expense reporting systems, least privilege reduces the attack surface and limits potential damage from compromised accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Defense in depth

    Why it's wrong here

    Defense in depth is a layered security strategy using multiple controls to protect assets; it does not strictly limit permissions per user role.

    When this WOULD be correct

    Defense in depth would be correct if the question described implementing multiple security layers (e.g., firewall, antivirus, encryption, and access controls) to protect the expense reporting application from various threats.

  • Least privilege

    Why this is correct

    This is the correct answer because the administrator is granting the minimal permissions required for each employee's role, directly applying the least privilege principle.

  • Separation of duties

    Why it's wrong here

    Separation of duties involves dividing critical tasks among multiple people to prevent fraud, not assigning minimal permissions per role.

    When this WOULD be correct

    A question where the administrator requires two different employees to approve and process expense reports to prevent a single person from both creating and approving payments would make separation of duties correct.

  • Zero trust

    Why it's wrong here

    Zero trust is a security model that assumes no implicit trust and continuously verifies every access request, but it does not specifically focus on granting minimal permissions.

    When this WOULD be correct

    A question describing a network architecture where every access request, even from inside the corporate network, must be authenticated, authorized, and encrypted, with micro-segmentation and continuous monitoring, would make zero trust the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Least privilegeCorrect answer

Why this is correct

This is the correct answer because the administrator is granting the minimal permissions required for each employee's role, directly applying the least privilege principle.

Defense in depthWrong answer — click to see why

Why this is wrong here

Defense in depth is a layered security strategy using multiple controls, not about limiting permissions to only what is needed. The question describes assigning minimal permissions per job role, which is least privilege.

★ When this WOULD be the correct answer

Defense in depth would be correct if the question described implementing multiple security layers (e.g., firewall, antivirus, encryption, and access controls) to protect the expense reporting application from various threats.

Why candidates choose this

Candidates may confuse defense in depth with least privilege because both involve multiple security measures, but defense in depth focuses on layers, not on minimizing permissions.

Separation of dutiesWrong answer — click to see why

Why this is wrong here

The scenario describes assigning permissions based on job needs, which is least privilege. Separation of duties involves splitting critical tasks among multiple people to prevent fraud, not limiting permissions to the minimum necessary.

★ When this WOULD be the correct answer

A question where the administrator requires two different employees to approve and process expense reports to prevent a single person from both creating and approving payments would make separation of duties correct.

Why candidates choose this

Candidates may confuse 'separation of duties' with 'least privilege' because both involve restricting access, but separation of duties focuses on dividing tasks to prevent conflicts of interest, not on minimizing permissions per role.

Zero trustWrong answer — click to see why

Why this is wrong here

Zero trust is a security model that assumes no implicit trust and requires continuous verification for every access request, but the question describes assigning minimal permissions based on job roles, which is the principle of least privilege, not zero trust.

★ When this WOULD be the correct answer

A question describing a network architecture where every access request, even from inside the corporate network, must be authenticated, authorized, and encrypted, with micro-segmentation and continuous monitoring, would make zero trust the correct answer.

Why candidates choose this

Candidates may confuse zero trust with least privilege because both involve restricting access, but zero trust is broader and includes continuous verification, while least privilege focuses on minimal permissions.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's IT department implements a policy for server administrators: they must submit an access request to perform privileged tasks on critical servers. Each request is approved by a manager, and the granted elevated permissions automatically expire after four hours. This approach reduces the risk of standing privileges being exploited. Which security concept is primarily being applied?

medium
  • A.Just-in-time access
  • B.Least privilege
  • C.Defense in depth
  • D.Zero Trust

Why A: Just-in-time (JIT) access is a security concept that grants elevated permissions only when needed, for a limited duration, and requires approval. In this scenario, the policy requires an access request, manager approval, and automatic expiration after four hours, which directly aligns with JIT access to reduce the risk of standing privileges being exploited.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.