nerdexam
(ISC)2

CCSP · Question #321

Access should be based on ____________. Response:

The correct answer is B. Business needs and acceptable risk. Access to resources should fundamentally align with an organization's business needs while also considering the acceptable level of associated risk.

Submitted by tunde_lagos· Apr 18, 2026Legal, Risk and Compliance

Question

Access should be based on ____________. Response:

Options

  • ARegulatory mandates
  • BBusiness needs and acceptable risk
  • CUser requirements and management requests
  • DOptimum performance and security provision

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    91% (20)
  • D
    5% (1)

Why each option

Access to resources should fundamentally align with an organization's business needs while also considering the acceptable level of associated risk.

ARegulatory mandates

While regulatory mandates inform security policies, they are not the sole basis for all access decisions, which should primarily derive from internal business operations.

BBusiness needs and acceptable riskCorrect

Access control policies should always be driven by genuine business requirements, ensuring users have only the necessary permissions to perform their job functions effectively. Simultaneously, an organization must evaluate the potential security risks associated with granting such access and establish an acceptable risk threshold to protect assets.

CUser requirements and management requests

User requirements and management requests are important inputs but must be vetted against actual business needs and the associated risks, not taken as the ultimate basis without further analysis.

DOptimum performance and security provision

Optimum performance and security provision are desired outcomes but do not define the underlying criteria for granting access rights.

Concept tested: Principles of access control

Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/design-access-control

Topics

#Access Control#Risk Management#Business Alignment#Security Governance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice