mediumMultiple Choice
ISC2 CC Practice Question: During a security audit, it is discovered that a…
During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?
⚠ Common exam trap
Watch out — candidates often confuse separation of duties with least privilege — candidates see 'one employee can do two things' and jump to least privilege, but the issue is the combination of conflicting duties, not excessive permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
Separation of duties (SoD) requires that no single individual controls all parts of a critical transaction or process. In this scenario, one employee can both approve purchase orders and receive the goods, meaning they could create a fictitious vendor, approve the payment, and confirm receipt of goods that never arrived — a classic fraud vector. SoD mandates that these two functions be split between different people so that collusion is required to commit fraud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties
Why this is correct
Separation of duties requires that no single person controls both authorisation and custody of an asset. One employee approving purchase orders and receiving the goods enables concealed fraudulent purchases, so splitting those responsibilities is the control being violated.
- ✗
Defense in depth
Why it's wrong here
Defence in depth layers multiple independent controls so one failure does not expose the system; it does not describe restricting a single person's combined duties. It is tempting because layered controls are a genuine audit concern, but the scenario describes one individual holding two conflicting transaction rights, which is separation of duties.
- ✗
Least privilege
Why it's wrong here
Least privilege grants only the minimum access needed for a role, but the employee legitimately holds both approval and receiving rights, so no excess permission exists. The violation is that these two conflicting duties reside in one person, which separation of duties prevents by splitting them across different individuals.
- ✗
Need-to-know
Why it's wrong here
Need-to-know limits access to information strictly required for a task; it governs data exposure, not the combination of transaction authorities. It is tempting because both concepts restrict access, but the purchase-order scenario concerns conflicting duties held by one employee, which separation of duties addresses.
Go deeper
Related to this question
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.