ISC2 CC Access Controls Concepts Practice Question
A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?
⚠ Common exam trap
The trap is confusing separation of duties with least privilege — both limit what a user can do, but SoD specifically requires multiple people to complete a task, while least privilege limits the scope of a single user's access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
Separation of duties (SoD) requires that critical tasks be divided among multiple people so that no single individual can complete a sensitive transaction alone. Requiring two managers to approve financial transactions is the textbook example: it prevents fraud and errors by ensuring collusion is needed to bypass the control. SoD is a foundational principle in ISC2's access control domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Need-to-know
Why it's wrong here
Need-to-know restricts data access to those whose duties require it, not transaction authorisation. The stem demands two independent approvers, which is separation of duties; need-to-know would instead limit which managers can view the financial records at all.
- ✗
Defense in depth
Why it's wrong here
Defence in depth stacks independent controls so one failure does not compromise the system. The stem instead requires two separate people to authorise one transaction, which is separation of duties; layering firewalls, badges and encryption would be defence in depth.
- ✗
Least privilege
Why it's wrong here
Least privilege grants users only the minimum rights needed for their role. The stem requires two distinct managers to approve one transaction, which is separation of duties; least privilege would instead limit each manager's permissions to their own function.
- ✓
Separation of duties
Why this is correct
Separation of duties splits a critical task across multiple identities so no single person controls it end to end. Requiring two distinct managers to approve each financial transaction enforces this by preventing one individual from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.