Courseiva
Access Controls Concepts →easyMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?

⚠ Common exam trap

The trap is confusing separation of duties with least privilege — both limit what a user can do, but SoD specifically requires multiple people to complete a task, while least privilege limits the scope of a single user's access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties

Separation of duties (SoD) requires that critical tasks be divided among multiple people so that no single individual can complete a sensitive transaction alone. Requiring two managers to approve financial transactions is the textbook example: it prevents fraud and errors by ensuring collusion is needed to bypass the control. SoD is a foundational principle in ISC2's access control domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Need-to-know

    Why it's wrong here

    Need-to-know restricts data access to those whose duties require it, not transaction authorisation. The stem demands two independent approvers, which is separation of duties; need-to-know would instead limit which managers can view the financial records at all.

  • ✗

    Defense in depth

    Why it's wrong here

    Defence in depth stacks independent controls so one failure does not compromise the system. The stem instead requires two separate people to authorise one transaction, which is separation of duties; layering firewalls, badges and encryption would be defence in depth.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege grants users only the minimum rights needed for their role. The stem requires two distinct managers to approve one transaction, which is separation of duties; least privilege would instead limit each manager's permissions to their own function.

  • ✓

    Separation of duties

    Why this is correct

    Separation of duties splits a critical task across multiple identities so no single person controls it end to end. Requiring two distinct managers to approve each financial transaction enforces this by preventing one individual from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.