TechKnowSurge
CompTIA Security+ 4.6 ISC2 CC 3.2 CompTIA Security+ 2.5 CompTIA Security+ 1.1 CompTIA Security+ 5.6
InteractiveSecurityFree

Personnel Security Principle Scenarios

Identify which personnel security principle — Least Privilege, Need to Know, Separation of Duties, Job Rotation, or Mandatory Vacation — each workplace scenario illustrates or violates.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Five principles, and the fastest way to tell them apart is to notice that each one answers a different question. Least Privilege asks how much a person can do: the help desk technician who can reset a password but cannot create or delete an account has been given the smallest set of actions the job needs, and the developer whose production credentials disappear when they move to a test role is the same principle enforced at the moment the role changes. Need to Know asks which information a person may see, and it bites even when the access level is already there — the finance analyst is trusted with budget data and still cannot open another department's payroll, and the HR employee has an HR account and is still fenced off from the CEO's compensation without a business reason on file. That pair is the first real trap in this activity. Both principles narrow access, so students reach for Least Privilege every time; the tell is whether the scenario is limiting the actions a role can perform or the specific records a person may read. Separation of Duties asks a third question entirely: can one person finish a sensitive transaction alone? The accountant who both approves purchase orders and processes the payments is the textbook violation, because approval and execution have collapsed into one pair of hands and no one else ever sees the transaction. The deploy that needs a second engineer and the teller transaction over ten thousand dollars that needs a manager's co-signature are the same idea working correctly — the point is never that the second person is more senior, only that there is a second person. The last two principles are the ones students misfile as HR paperwork, and the objective here is to stop doing that. Job Rotation and Mandatory Vacation prevent almost nothing; they are detective controls, and what they detect is the fraud that only survives because the same person keeps sitting in the same seat. A scheme that requires continuous tending — a suppressed alert, a reconciliation that never quite balances, a backup that has not actually been restorable for a year — comes apart the moment somebody else does the job. That is the whole mechanism, and it is why the IT administrator with sole access to the backup system who has not taken leave in three years is a finding rather than a dedicated employee. Distinguishing those last two from each other is the second real trap, and two items are a deliberate near-pair. The admin who swaps roles with a peer annually is Job Rotation: they change jobs, and each one now sees the work the other used to own. The policy requiring a co-worker to cover every employee's duties for two weeks a year is Mandatory Vacation: nobody changes jobs, somebody is simply absent from theirs while another person sits down at it. Rotation moves the person to new work; vacation moves the work to a new person and hands the original back on return. Three items in this set are violations rather than clean examples, and the bin is still the principle at stake — the employee carrying permissions from three previous positions is filed under Least Privilege because access creep is exactly what Least Privilege exists to prevent. One note for the exam room: Security+ SY0-701 names least privilege directly in objectives 2.5 and 4.6 but does not list separation of duties, job rotation or mandatory vacation as subtopics anywhere, treating them under the broader control-type language of objective 1.1; ISC2's CC outline is the one that names Least Privilege and Separation of Duties together, under logical access controls. The distinctions you are drilling here are the ones both exams test — only the objective sheet's wording differs.

What you'll learn

Aligned to

CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
2.5 Explain the purpose of mitigation techniques used to secure the enterprise.
1.1 Compare and contrast various types of security controls.
5.6 Given a scenario, implement security awareness practices.
ISC2 CC
3.2 Understand logical access controls

Key terms

Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Need-to-Know
A security principle that limits access to sensitive information only to individuals who require it to perform their job functions, reducing the organizational attack surface.
Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.
Job Rotation
A personnel security control that moves employees between roles periodically to reduce the risk of fraud and uncover irregularities.
Mandatory Vacation
A policy requiring employees to take scheduled time away from their duties, allowing organizations to detect fraudulent or unauthorized activity in their absence.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Administrative Control
A cybersecurity control based on policies, procedures, and checklists that guide how an organization manages and implements its security practices.
Privileged Access Management
PAM
Privileged Access Management encompasses the policies, tools, and technologies used to control, monitor, and audit access by privileged accounts such as administrators, reducing insider threat risk through just-in-time access grants and full session recording.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →