SY0-701 General Security Concepts Practice Question
Which three of the following are commonly used to enforce separation of duties? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse separation of duties with least privilege or fail to recognize that combining authorization and implementation in one role is a direct violation, even if it seems efficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requiring two different people to authorize a financial transaction
Separation of duties is a security principle that prevents any single individual from having excessive control over critical processes. Requiring two different people to authorize a financial transaction ensures that no one person can both initiate and approve a payment, reducing fraud risk. Splitting the ability to create user accounts and assign privileges to different roles ensures that a single administrator cannot grant themselves unauthorized access. Using a dual-control process where two keys are needed to access a safe physically enforces that two people must be present, preventing unilateral access to sensitive assets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Requiring two different people to authorize a financial transaction
Why this is correct
It requires two distinct individuals to perform two critical steps in a transaction, ensuring that no single person can initiate and approve a payment independently. This preventive control forces collusion for fraud to occur, which significantly increases the probability of detection. It is a fundamental financial control that aligns with the principle of separation of duties.
- ✓
Splitting the ability to create user accounts and assign privileges to different roles
Why this is correct
This control splits the identity lifecycle into separate functions: account creation and privilege assignment are each owned by different roles. As a result, a user administrator cannot grant themselves or a colleague elevated permissions without a second individual's action, mitigating insider threat risks. This enforces accountability and supports the principle of least privilege within the identity and access management framework.
- ✓
Using a dual-control process where two keys are needed to access a safe
Why this is correct
Dual-control requires two authorized persons to be physically present at the same time, each holding a different key or credential, to unlock the safe. No single individual can access the contents alone, so any attempt to steal or tamper with the asset would require another person's active participation, thereby deterring insider theft. This is a physical manifestation of separation of duties.
- ✗
Allowing a single administrator to both approve and implement system changes
Why it's wrong here
This configuration combines the change approval and implementation steps into one person's authority, eliminating the independent review normally required to catch unauthorized or flawed modifications. Without a second person to inspect the change, errors could be deployed silently, and the approval record is meaningless because the same person can act on their own request. The control is invalid because approval and implementation are mutually exclusive duties.
- ✗
Giving one person full responsibility for both IT security audits and daily operations
Why it's wrong here
Having the same person responsible for both conducting IT security audits and performing daily operations compromises the audit's objectivity, as the auditor would be examining their own work. This conflict of interest can shield operational problems from detection and reduce the reliability of audit findings. Separation of duties requires audit responsibilities to be independent of the areas being audited.
- ✗
Configuring a single user to manage both backup and restoration of data
Why it's wrong here
If a single user is responsible for both creating and restoring backups, that user could delete or corrupt backup files and then restore an older, unauthorized version, or cover up a security incident. This role combination also makes it impossible to attribute data changes to distinct individuals. Separating backup and restoration responsibilities ensures that data recovery actions are independently verified and logged.
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.