CISSP Practice Question: In the context of Identity and Access Management (IAM), what is the…
Correct Answer: C. C. Users should have only the access needed to perform their job functions
Explanation (CISSP Manager Logic):
Least privilege is a fundamental risk management strategy that minimizes the potential impact of accidental or intentional insider threats. By restricting access to the minimum necessary for business operations, managers reduce the organization's attack surface and ensure accountability.
By implementing this solution, you:
- Limit the blast radius of a compromised user account.
- Enforce strict data confidentiality and integrity standards.
- Simplify compliance auditing by mapping access directly to job roles.
While the other options are relevant, they fall short because:
- A: Default access to all resources creates an unmanageable security risk and violates basic control principles.
- B: Maximum access grants excessive permissions that are unnecessary for daily tasks and invites abuse.
- D: Seniority is a HR metric, not a security requirement, and does not reflect actual operational needs.
Think like a manager:
Prioritize "need to know" over convenience to protect organizational assets. Effective security management requires balancing operational efficiency with the mitigation of unauthorized data exposure.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial