ISC2 CC Access Controls Concepts Practice Question
A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)
⚠ Common exam trap
The trap is that candidates confuse separation of duties with least privilege or dual control — option E looks security-related but is least privilege, and option C is the classic 'toxic combination' that SoD is designed to prevent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
One employee creates a purchase order, another approves it
Option A is correct because separation of duties requires that no single person controls an entire transaction; having one employee create a purchase order while a different employee approves it splits the critical functions of initiation and authorization. Option B is correct because requiring two managers to approve any payment over $5,000 enforces dual control (two-person integrity), ensuring that high-value transactions cannot be executed by one individual acting alone. Option C is incorrect because allowing a manager to both initiate and approve a wire transfer concentrates incompatible duties in one person, which is the exact opposite of separation of duties. Option D is incorrect because sharing the same password for the accounting system destroys individual accountability and non-repudiation, and it is a poor authentication practice rather than a separation-of-duties control. Option E is incorrect because read-only access to financial reports is an example of least privilege, not separation of duties, since it does not divide transaction responsibilities among multiple people.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
One employee creates a purchase order, another approves it
Why this is correct
Splitting the purchase order creation from its approval across two employees enforces separation of duties: no single person controls the whole transaction. This directly satisfies the stem's requirement by preventing one individual from both initiating and authorising financial payments, reducing fraud risk.
- ✓
Two managers must approve any payment over $5,000
Why this is correct
Requiring two managers to approve payments above $5,000 implements dual control, a separation-of-duties variant. It satisfies the stem's financial transaction constraint by ensuring no single manager can authorise a high-value payment alone, preventing unilateral fraud.
- ✗
A manager can both initiate and approve a wire transfer
Why it's wrong here
Allowing one manager to both initiate and approve the same wire transfer concentrates two conflicting duties in a single person, directly violating separation of duties. It is tempting because small teams often lack staff to split roles, and this arrangement would be acceptable only where no segregation requirement or compensating control exists.
- ✗
All employees use the same password for the accounting system
Why it's wrong here
Shared passwords across all accounting employees destroy individual accountability, so no transaction can be attributed to a person and no duties can be separated. Password sharing is tempting for reducing helpdesk load, but it would only be defensible in a generic shared low-risk account, never for financial transactions.
- ✗
A user has read-only access to financial reports
Why it's wrong here
Read-only access to financial reports is least privilege, restricting what a user can change, rather than separation of duties, which splits a sensitive process across different people. Least privilege would be the right answer if the question asked how to limit a single user's permissions.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.