nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #219

What security principle is being adhered to when a user's access request is declined, despite meeting the necessary security clearance, because there is no business justification for the access?

The correct answer is C. Need to know. The 'Need to Know' principle dictates that having a sufficient security clearance level is not enough on its own - the individual must also have a legitimate business justification (a 'need to know') to access specific information or resources. This is distinct from Least…

Access Controls Concepts

Question

What security principle is being adhered to when a user's access request is declined, despite meeting the necessary security clearance, because there is no business justification for the access?

Options

  • ASeparation of duties
  • BTwo-person control
  • CNeed to know
  • DLeast privilege

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    88% (28)
  • D
    6% (2)

Explanation

The 'Need to Know' principle dictates that having a sufficient security clearance level is not enough on its own - the individual must also have a legitimate business justification (a 'need to know') to access specific information or resources. This is distinct from Least Privilege (granting only minimum permissions needed for a job function) and Separation of Duties (dividing critical tasks among multiple people). The scenario specifically highlights the absence of a business justification as the reason for denial, which is the hallmark of Need to Know.

Topics

#Access Control#Security Principles#Need to Know#Information Security

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice