SY0-701 exam dumps

SY0-701 practice question 140 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 140

Single answerLeast privilege

A company is preparing for an external audit after a ransomware incident. The security team discovers that help desk technicians have been assigned local administrator rights on all employee laptops so they can install drivers and troubleshoot software issues quickly. Audit logs show that malware executed under one technician's account was able to disable endpoint protections on several systems. The IT manager wants to reduce this risk without preventing technicians from performing their normal support tasks. Which action is the BEST way to apply least privilege in this situation?

  1. A

    Remove local administrator rights from help desk accounts and require technicians to use separate privileged accounts only when elevated access is specifically needed

  2. B

    Keep local administrator rights assigned to help desk accounts, but require technicians to change their passwords every 30 days

  3. C

    Add application allowlisting to all laptops, but continue using the same administrator accounts for daily help desk work

  4. D

    Grant all employees temporary local administrator rights so they can install approved software without opening support tickets

Show answer and explanation

Correct answer: A

Explanation

Least privilege means users and accounts should have only the minimum access necessary to perform assigned tasks. In this scenario, the main issue is that help desk staff are using highly privileged accounts for routine work, which allowed malware to disable protections when one account was compromised. The strongest corrective action is to remove unnecessary admin rights from day-to-day accounts and require use of separate privileged accounts or just-in-time elevation only for approved administrative tasks. This approach is consistent with widely accepted security guidance, including principles described by NIST and Microsoft's privileged access security recommendations: administrative tasks should be performed with dedicated privileged identities, not standard user accounts used for email, browsing, and general support work. While controls such as password policies and application allowlisting are valuable, they do not replace proper privilege restriction.

  • A. Correct.

    Correct. This is the best application of least privilege because it removes unnecessary administrative rights from technicians' everyday accounts and limits elevation to only those situations that require it. Using separate privileged accounts reduces the chance that malware, phishing, or routine browsing performed under a standard account will inherit administrative permissions. This aligns with common best practices for privileged access management and administrative tiering.

  • B. Incorrect.

    Incorrect. More frequent password changes do not address the core least privilege problem: technicians still perform routine activities with excessive permissions. If malware runs in the context of an administrator account, it can still make system-level changes regardless of password age. This option focuses on credential hygiene rather than reducing privileges.

  • C. Incorrect.

    Incorrect. Application allowlisting can reduce unauthorized software execution, but it does not directly fix the issue of excessive privileges on technician accounts. If the same account used for email, web access, and daily work still has administrator rights, compromise of that account can still have broad impact. This is a useful compensating control, but not the best answer for applying least privilege.

  • D. Incorrect.

    Incorrect. This increases risk rather than reducing it. Granting broad administrative rights to more users violates least privilege and expands the attack surface. Even if the rights are temporary, this approach creates unnecessary exposure and weakens control over software installation and endpoint security.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam