ISC2 CC Access Controls Concepts Practice Question
An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
⚠ Common exam trap
CC often tests the overlap between separation of duties and least privilege, so candidates see 'restrict access' language and pick least privilege when the scenario is really about splitting authority across two people.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
Requiring two separate approvals for a high-value transaction is the classic definition of separation of duties: no single individual has enough authority to complete a sensitive action alone. This prevents fraud and error by distributing control across multiple people.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties
Why this is correct
Separation of duties splits a sensitive task across multiple people so no single individual holds end-to-end authority. Requiring a second manager's approval for transactions above $10,000 enforces this by preventing one employee from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.
- ✗
Least privilege
Why it's wrong here
Least privilege limits each identity's permissions to the minimum required; it does not require two people to jointly authorise one action. It is tempting because both principles constrain authority, and it would be correct where the requirement is scoping a role's rights rather than preventing unilateral approval of a transaction.
- ✗
Need-to-know
Why it's wrong here
Need-to-know restricts access to information a subject requires for a task; it does not mandate dual approval of a transaction. It is tempting because it also embodies minimal access, and it would be correct where the requirement is limiting which data an employee may view rather than requiring two authorisers.
- ✗
Defense in depth
Why it's wrong here
Defence in depth layers independent controls so that breaching one does not grant access; here the requirement is that two distinct people each authorise the same transaction, which is separation of duties. Layering perimeter firewalls, endpoint protection and physical locks would be defence in depth.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.