Courseiva
Access Controls Concepts →hardMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)

⚠ Common exam trap

The trap is that candidates confuse separation of duties with least privilege or dual control — option E looks security-related but is least privilege, and option C is the classic 'toxic combination' that SoD is designed to prevent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

One employee creates a purchase order, another approves it

Option A is correct because separation of duties requires that no single person controls an entire transaction; having one employee create a purchase order while a different employee approves it splits the critical functions of initiation and authorization. Option B is correct because requiring two managers to approve any payment over $5,000 enforces dual control (two-person integrity), ensuring that high-value transactions cannot be executed by one individual acting alone. Option C is incorrect because allowing a manager to both initiate and approve a wire transfer concentrates incompatible duties in one person, which is the exact opposite of separation of duties. Option D is incorrect because sharing the same password for the accounting system destroys individual accountability and non-repudiation, and it is a poor authentication practice rather than a separation-of-duties control. Option E is incorrect because read-only access to financial reports is an example of least privilege, not separation of duties, since it does not divide transaction responsibilities among multiple people.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    One employee creates a purchase order, another approves it

    Why this is correct

    Splitting the purchase order creation from its approval across two employees enforces separation of duties: no single person controls the whole transaction. This directly satisfies the stem's requirement by preventing one individual from both initiating and authorising financial payments, reducing fraud risk.

  • ✓

    Two managers must approve any payment over $5,000

    Why this is correct

    Requiring two managers to approve payments above $5,000 implements dual control, a separation-of-duties variant. It satisfies the stem's financial transaction constraint by ensuring no single manager can authorise a high-value payment alone, preventing unilateral fraud.

  • ✗

    A manager can both initiate and approve a wire transfer

    Why it's wrong here

    Allowing one manager to both initiate and approve the same wire transfer concentrates two conflicting duties in a single person, directly violating separation of duties. It is tempting because small teams often lack staff to split roles, and this arrangement would be acceptable only where no segregation requirement or compensating control exists.

  • ✗

    All employees use the same password for the accounting system

    Why it's wrong here

    Shared passwords across all accounting employees destroy individual accountability, so no transaction can be attributed to a person and no duties can be separated. Password sharing is tempting for reducing helpdesk load, but it would only be defensible in a generic shared low-risk account, never for financial transactions.

  • ✗

    A user has read-only access to financial reports

    Why it's wrong here

    Read-only access to financial reports is least privilege, restricting what a user can change, rather than separation of duties, which splits a sensitive process across different people. Least privilege would be the right answer if the question asked how to limit a single user's permissions.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.