Courseiva
Access Controls Concepts →hardMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?

⚠ Common exam trap

CC often tests the overlap between separation of duties and least privilege, so candidates see 'restrict access' language and pick least privilege when the scenario is really about splitting authority across two people.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties

Requiring two separate approvals for a high-value transaction is the classic definition of separation of duties: no single individual has enough authority to complete a sensitive action alone. This prevents fraud and error by distributing control across multiple people.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Separation of duties

    Why this is correct

    Separation of duties splits a sensitive task across multiple people so no single individual holds end-to-end authority. Requiring a second manager's approval for transactions above $10,000 enforces this by preventing one employee from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege limits each identity's permissions to the minimum required; it does not require two people to jointly authorise one action. It is tempting because both principles constrain authority, and it would be correct where the requirement is scoping a role's rights rather than preventing unilateral approval of a transaction.

  • ✗

    Need-to-know

    Why it's wrong here

    Need-to-know restricts access to information a subject requires for a task; it does not mandate dual approval of a transaction. It is tempting because it also embodies minimal access, and it would be correct where the requirement is limiting which data an employee may view rather than requiring two authorisers.

  • ✗

    Defense in depth

    Why it's wrong here

    Defence in depth layers independent controls so that breaching one does not grant access; here the requirement is that two distinct people each authorise the same transaction, which is separation of duties. Layering perimeter firewalls, endpoint protection and physical locks would be defence in depth.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.