Courseiva
easyMultiple Choice

CISA Practice Question: Is a requirement for effective segregation of…

Which of the following is a requirement for effective segregation of duties in IT?

⚠ Common exam trap

The trap is selecting an option that sounds efficient or expertise-building (same person develops/tests/deploys, or admins audit) when it actually destroys the independence and checks that SoD is designed to provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Different individuals should be responsible for authorizing, executing, and reconciling transactions.

Segregation of duties requires that no single individual controls all stages of a transaction or process; the classic model separates authorization, execution (custody), and reconciliation/recording. Assigning these to different individuals prevents fraud and undetected errors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All IT staff should have access to production data for troubleshooting.

    Why it's wrong here

    Granting all IT staff production data access violates least privilege and removes the boundary between those who administer systems and those who handle data. It is tempting because broad access aids troubleshooting, but segregation of duties requires restricting production access to authorised, separate roles.

  • ✗

    System administrators should also perform internal audits to maintain expertise.

    Why it's wrong here

    System administrators auditing their own systems creates a self-review threat, since they would assess controls they operate. It is tempting because administrators know the environment intimately, yet independence demands that internal audit be performed by personnel outside the functions being audited.

  • ✗

    The same person should develop, test, and deploy code to ensure consistency.

    Why it's wrong here

    Combining development, testing, and deployment in one person concentrates incompatible duties, removing the independent verification segregation of duties requires. It is tempting because a single developer owning the lifecycle appears to speed delivery, yet that is precisely the control weakness the requirement exists to prevent.

  • ✓

    Different individuals should be responsible for authorizing, executing, and reconciling transactions.

    Why this is correct

    Segregation of duties splits incompatible functions across people so no single individual controls a transaction end to end. Assigning authorisation, execution and reconciliation to different individuals prevents both error and fraud going undetected, which is the requirement stated.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.