ISC2 CC Security Principles Practice Question
A retail company's security policy states that no single employee should be able to both create a vendor payment and approve it. The company assigns these duties to two different people. Which security principle is the policy enforcing?
⚠ Common exam trap
Many candidates confuse separation of duties with least privilege, since both restrict what a user can do, but only separation of duties requires two different people in one workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
The policy prevents any single employee from completing a sensitive transaction end to end by requiring two different people to create and approve a vendor payment. That is separation of duties, an administrative control that limits the opportunity for fraud and error. Least privilege limits what each user can access, defense in depth layers controls, and job rotation changes assignments over time; none of those captures the requirement that two distinct people must be involved in one process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties
Why this is correct
Separation of duties divides a critical task among multiple people so that no single individual can complete it without detection or collusion. Here, creating a vendor payment and approving it are deliberately assigned to two different employees, preventing one person from initiating and authorizing a fraudulent payment. This directly matches the policy's intent and is a classic detective and preventive administrative control in financial and security operations.
- ✗
Least privilege
Why it's wrong here
Least privilege means giving users only the minimum access required to perform their job, and it is often implemented through role-based access control. While related, the scenario is not about reducing the breadth of each user's permissions; it is about splitting one business process across two people so neither can complete a fraudulent transaction alone. Least privilege alone would not prevent a single fully authorized user from both creating and approving a payment.
- ✗
Job rotation
Why it's wrong here
Job rotation moves employees through different roles over time to broaden skills and to surface fraud or errors that a permanently assigned person might conceal. The policy here permanently assigns two distinct duties to two different individuals rather than rotating them through each other's positions. Rotation could complement separation of duties, but it is not the principle that requires the creator and approver of a payment to be different people.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls so that if one fails, others still protect the asset. The scenario describes a single administrative control that splits a workflow between two roles, not a stack of overlapping technical, physical, and administrative safeguards. Applying defense in depth might add logging or manager review on top, but it does not by itself describe why two separate employees handle payment creation and approval.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.