SY0-701 General Security Concepts Practice Question
A security auditor is reviewing the access controls for a payroll application. The auditor discovers that a single user, the payroll manager, has permissions to both create new employee records and then approve and process salary payments for those records. The company's security policy requires that no single individual should be able to execute both the creation and the approval of a payment for the same employee. Which of the following security principles is the company's policy attempting to enforce?
⚠ Common exam trap
Many exam-takers confuse separation of duties with least privilege, but the key distinction is that separation of duties focuses on dividing conflicting tasks among multiple users to prevent fraud, while least privilege focuses on limiting permissions to the minimum needed for a single user's role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
The company's policy prohibits a single user from both creating employee records and approving payments for them, which is a classic application of separation of duties. This principle ensures that no single individual has the authority to execute two conflicting or sensitive tasks that could lead to fraud or error, such as creating a fictitious employee and then approving a salary payment to that employee. In the context of a payroll application, separation of duties requires distinct roles or users for record creation and payment approval to enforce checks and balances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege limits each user's account to the minimum set of permissions required to perform their assigned duties, such as granting a data analyst read-only access to a spreadsheet. It reduces the blast radius of a compromised credential, but the policy under review is fundamentally different because it requires two or more people to cooperate to complete a high-risk action, rather than simply giving each person narrow permissions. In practice, least privilege and separation of duties are complementary, but the described control is specifically about splitting responsibilities, not just minimizing permissions.
When this WOULD be correct
A question where a user has more permissions than needed for their job role, such as a help desk technician having administrative rights to modify system files. The correct answer would be least privilege because the policy aims to restrict permissions to only those required.
- ✓
Separation of duties
Why this is correct
Separation of duties (SoD) is a preventive administrative control that fragments critical transaction phases—such as authorization, custody, and recordkeeping—across different individuals. In this scenario, the policy ensures that no single person can both initiate and approve a high-risk change, because combining those capabilities would allow an insider to create and conceal fraudulent activity. SoD directly addresses the requirement by forcing collusion or at least independent oversight for sensitive operations.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a layered security architecture strategy that uses overlapping controls such as perimeter firewalls, intrusion prevention systems, antivirus, and full-disk encryption to protect assets. It slows or stops an attacker who bypasses one layer by presenting a different control at the next layer, but it does not define how tasks or privileges are divided among users. Therefore, while defense in depth is a security best practice, it is not the policy being described for splitting functional responsibilities.
When this WOULD be correct
A company implements firewalls, intrusion detection, antivirus, and access controls to protect a network. An auditor asks which security principle this layered approach represents. The correct answer would be defense in depth.
- ✗
Mandatory access control
Why it's wrong here
Mandatory access control (MAC) is an operating system-level authorization model in which the system, not the user, enforces restrictions based on fixed security labels and clearances, such as Top Secret, Secret, and Confidential. Subjects and objects are tagged, and a central security policy dictates read/write permissions, so MAC does not assign different users to separate steps of a business process. Thus, MAC is a system-enforced data classification mechanism, not a framework for segregating duties among roles.
When this WOULD be correct
A question where a system uses security labels (e.g., Top Secret, Secret) to enforce access based on user clearance and data classification, and the policy requires that users cannot change labels or override system-enforced rules. For example: 'A military system requires that only users with a Top Secret clearance can read Top Secret documents, and the system enforces this automatically.'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Separation of dutiesCorrect answer▾
Why this is correct
Separation of duties (SoD) is a preventive administrative control that fragments critical transaction phases—such as authorization, custody, and recordkeeping—across different individuals. In this scenario, the policy ensures that no single person can both initiate and approve a high-risk change, because combining those capabilities would allow an insider to create and conceal fraudulent activity. SoD directly addresses the requirement by forcing collusion or at least independent oversight for sensitive operations.
✗Least privilegeWrong answer — click to see why▾
Why this is wrong here
The policy specifically targets preventing a single user from performing both creation and approval of payments, which is the core of separation of duties, not least privilege. Least privilege would limit permissions to only what is necessary for a role, but here the issue is conflicting duties.
★ When this WOULD be the correct answer
A question where a user has more permissions than needed for their job role, such as a help desk technician having administrative rights to modify system files. The correct answer would be least privilege because the policy aims to restrict permissions to only those required.
Why candidates choose this
Candidates may confuse 'least privilege' with 'separation of duties' because both involve limiting user permissions, but they address different risks: least privilege reduces overall access, while separation of duties prevents fraud by splitting conflicting tasks.
✗Defense in depthWrong answer — click to see why▾
Why this is wrong here
Defense in depth is a layered security strategy using multiple controls, not a principle preventing a single user from performing conflicting duties. The scenario describes a conflict of interest, not a lack of multiple security layers.
★ When this WOULD be the correct answer
A company implements firewalls, intrusion detection, antivirus, and access controls to protect a network. An auditor asks which security principle this layered approach represents. The correct answer would be defense in depth.
Why candidates choose this
Candidates may confuse 'separation of duties' with 'defense in depth' because both involve multiple layers or checks, but defense in depth focuses on overlapping controls rather than dividing responsibilities among individuals.
✗Mandatory access controlWrong answer — click to see why▾
Why this is wrong here
Mandatory access control (MAC) is a model where access decisions are based on system-enforced labels (e.g., security clearance), not on preventing a single user from performing conflicting tasks. The policy described is about separating duties, not about label-based access.
★ When this WOULD be the correct answer
A question where a system uses security labels (e.g., Top Secret, Secret) to enforce access based on user clearance and data classification, and the policy requires that users cannot change labels or override system-enforced rules. For example: 'A military system requires that only users with a Top Secret clearance can read Top Secret documents, and the system enforces this automatically.'
Why candidates choose this
Candidates may confuse 'separation of duties' with 'mandatory access control' because both involve restrictions, but MAC is about label-based enforcement, not about splitting conflicting tasks among multiple users.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.