Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: During a security audit, it is discovered that a…

During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?

⚠ Common exam trap

Watch out — candidates often confuse separation of duties with least privilege — candidates see 'one employee can do two things' and jump to least privilege, but the issue is the combination of conflicting duties, not excessive permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties

Separation of duties (SoD) requires that no single individual controls all parts of a critical transaction or process. In this scenario, one employee can both approve purchase orders and receive the goods, meaning they could create a fictitious vendor, approve the payment, and confirm receipt of goods that never arrived — a classic fraud vector. SoD mandates that these two functions be split between different people so that collusion is required to commit fraud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Separation of duties

    Why this is correct

    Separation of duties requires that no single person controls both authorisation and custody of an asset. One employee approving purchase orders and receiving the goods enables concealed fraudulent purchases, so splitting those responsibilities is the control being violated.

  • ✗

    Defense in depth

    Why it's wrong here

    Defence in depth layers multiple independent controls so one failure does not expose the system; it does not describe restricting a single person's combined duties. It is tempting because layered controls are a genuine audit concern, but the scenario describes one individual holding two conflicting transaction rights, which is separation of duties.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege grants only the minimum access needed for a role, but the employee legitimately holds both approval and receiving rights, so no excess permission exists. The violation is that these two conflicting duties reside in one person, which separation of duties prevents by splitting them across different individuals.

  • ✗

    Need-to-know

    Why it's wrong here

    Need-to-know limits access to information strictly required for a task; it governs data exposure, not the combination of transaction authorities. It is tempting because both concepts restrict access, but the purchase-order scenario concerns conflicting duties held by one employee, which separation of duties addresses.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.