Courseiva
Access Controls Concepts →hardMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)

⚠ Common exam trap

The trap here is equating trust in a specific person with an effective control, which leads candidates to accept consolidating payment duties as a reasonable simplification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying a system constraint that prevents the same user account from both entering and approving a payment

Separation of duties ensures no single person can complete a sensitive transaction end to end. Requiring different employees to initiate and approve payments, and enforcing that split with a system constraint that blocks one account from doing both, both create an independent check. The other practices concentrate or allow circumvention of those duties, which undermines the control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Granting one senior manager both the ability to create vendors and the ability to approve payments to those vendors

    Why it's wrong here

    Combining vendor creation with payment approval lets one person introduce a fictitious vendor and then authorize payment to it, which defeats separation of duties. This concentration of duties is the risk the firm is trying to prevent. Even a trusted senior manager should not hold both capabilities, so this practice weakens rather than supports the control.

  • ✗

    Allowing any employee with payment approval rights to also modify the approval limits assigned to their own account

    Why it's wrong here

    Letting approvers change their own limits lets them raise the threshold above the payments they want to push through, bypassing oversight. This undermines separation of duties because the person acting can also alter the rules governing that action. Approval limits should be set by someone independent, so this practice is unsafe.

  • ✗

    Assigning all payment-related duties to a single trusted administrator to simplify the process

    Why it's wrong here

    Consolidating every payment duty into one administrator removes the independent check that separation of duties requires, creating a single point of abuse. Trust in the individual does not substitute for a structural control, because the risk is inherent in the design. This approach simplifies work at the cost of the very protection the firm is trying to build.

  • ✓

    Applying a system constraint that prevents the same user account from both entering and approving a payment

    Why this is correct

    A technical constraint that blocks one account from performing both steps enforces separation of duties automatically rather than relying on policy alone. It removes the possibility of a single user completing the whole transaction, which is exactly what the firm needs. This makes the control reliable and auditable in the payment system.

  • ✓

    Requiring one employee to initiate a payment and a different employee to approve it

    Why this is correct

    Splitting initiation and approval between two people prevents any single individual from completing a payment alone, which is the core of separation of duties. It ensures an independent check exists before funds move, reducing the risk of fraud or error. This directly enforces the control the firm is designing for its payment process.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.