ISC2-CC - Access Controls Concepts (22% of the exam) - Section 3.3

Apply the principles of least privilege, need-to-know, and segregation of duties, including privileged access management.

Apply least privilege - granting users only the access required for their tasks - alongside need-to-know and segregation of duties, which splits a sensitive task so no single person can complete it alone. Recognise privileged access management (PAM) as the discipline that controls, monitors, and time-bounds elevated administrator accounts.

Least privilegeNeed-to-knowSegregation of dutiesPrivileged access management

Practice question for this objective

Free sampleAccess Controls Conceptsmedium

A manager asks why an organisation would route all administrator logins through a dedicated privileged access management system that brokers the session and records what the administrator does. Which statement best explains the primary security purpose of that arrangement?

  • AIt encrypts network traffic so that administrator passwords cannot be intercepted between the client and the server
  • BIt replaces the need for least privilege by giving administrators one convenient account for every system
  • CIt controls, monitors, and records the use of high-risk privileged accounts so their activity is governed and auditable Correct
  • DIt guarantees that administrators can never make configuration mistakes while managing production systems
Privileged access management controls, monitors, and records the use of high-risk privileged accounts to make their activity accountable. Privileged accounts carry outsized power, so brokering their sessions and recording their actions makes that high-risk activity governable and auditable, which is the central goal of privileged access management.

Why A is wrong: Encrypting traffic protects credentials in transit and is worthwhile, but it is not the primary purpose of brokering and recording privileged sessions.

Why B is wrong: This is the opposite of good practice; privileged access management supports least privilege rather than replacing it, and consolidating power into one account would increase risk.

Why C is correct: This states the core aim of privileged access management: to broker, constrain, and log the use of powerful accounts so their high-risk activity is accountable and reviewable.

Why D is wrong: No system can guarantee error-free administration; privileged access management reduces and records risk but does not prevent all mistakes, so this overstates its function.

See more ISC2-CC practice questions, answers explained.

Exam traps in Access Controls Concepts

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • Rotate the developers through different project teams every quarter so that no one keeps the same administrative duties for long.

    Why it is wrong: Job rotation can deter and reveal misuse over time, but it leaves the standing admin rights in place, so the constant exposure the team wants to remove is unchanged.

  • Single sign-on, which lets a subject authenticate once and reach multiple systems without signing in again

    Why it is wrong: Single sign-on concerns convenient authentication across systems; it does not describe granting and then withdrawing elevated rights for a time-boxed task.

  • Need-to-know, which restricts access to particular information based on a demonstrated requirement to see it

    Why it is wrong: Need-to-know is closely related and tempting, but it governs access to specific information rather than the broader set of system rights and permissions described here.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.