hardMultiple Choice
ISC2 CC Practice Question: A financial institution requires that no single…
A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?
⚠ Common exam trap
The trap is confusing separation of duties with least privilege or need to know; candidates must recognize that SoD specifically addresses the division of a single task among multiple people to prevent conflicts of interest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
Separation of duties is the security principle that requires multiple individuals to complete a task to prevent fraud and errors. By ensuring no single employee can both initiate and approve a wire transfer, the institution enforces this principle, reducing the risk of unauthorized transactions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties
Why this is correct
Separation of duties splits a sensitive transaction across two people so no single employee holds end-to-end control. Requiring one person to initiate and a different person to approve the wire transfer enforces exactly this split, preventing unilateral fraud.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls; the scenario describes one control splitting a transaction across two people. It is tempting because defense in depth is genuinely correct when a single safeguard failing must not compromise the asset.
- ✗
Least privilege
Why it's wrong here
Least privilege limits each user to the minimum access required, but both employees here retain their respective permissions; the split of duties is what prevents fraud. It is tempting because least privilege is genuinely correct when accounts hold excessive rights beyond their role.
- ✗
Need to know
Why it's wrong here
Need to know restricts access to information according to job requirements; it does not separate the authority to initiate from the authority to approve. It is tempting because need to know is genuinely correct when the concern is limiting which data an employee may view.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.