hardMultiple Choice
Separation of Duties Violation: How a Configuration Error Circumvents Dual Approval
A financial institution is implementing a new transaction approval process. The process requires that for any transaction over $10,000, two managers must approve: one from the sales department and one from the finance department. However, due to a system configuration error, a single manager can approve the entire transaction if they are logged in from a specific IP address. This error is discovered during a routine audit. Which security principle has been circumvented, and what is the best remediation?
Quick Answer
The answer is separation of duties, and the best remediation is to fix the configuration to require approvals from two different managers. This security principle is circumvented because the configuration error allows a single manager to approve a high-value transaction by exploiting a specific IP address, effectively bypassing the dual-approval requirement that ensures no single individual has unchecked control over critical financial processes. On the ISC2 Certified in Cybersecurity CC exam, this scenario tests your understanding of how technical misconfigurations can undermine foundational security controls; a common trap is choosing a remediation that adds extra layers like logging or escalation instead of simply correcting the root flaw. Remember the memory tip: “Two eyes, one fix” — when a dual-approval rule is broken, the fix is always to restore the rule, not to add more rules.
⚠ Common exam trap
CC often tests the application of security principles to scenarios; candidates might confuse separation of duties with least privilege or defense in depth, but the key is recognizing that dual approval is a separation of duties control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties; fix the configuration to require approvals from two different managers
The scenario describes a situation where a single manager can approve a transaction that should require two separate approvals from different departments. This circumvents the separation of duties principle, which ensures that no single individual has the authority to complete a critical task alone. The best remediation is to fix the configuration so that two different managers must approve, restoring separation of duties. Defense in depth (B) is about layered controls, accountability (C) is about logging, and least privilege (D) is about minimal access rights; none directly address the bypass of dual approval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties; fix the configuration to require approvals from two different managers
Why this is correct
Two distinct approvers from sales and finance enforce separation of duties, preventing one person completing the whole transaction. The IP-based bypass collapses both approvals into a single actor, so the control fails. Remediation is to correct the configuration so two different managers must approve, restoring the dual-authorisation constraint.
- ✗
Defense in depth; add a third approval for transactions over $50,000
Why it's wrong here
Adding a third approval threshold leaves the single-approver IP bypass intact, so separation of duties is still defeated for transactions between $10,000 and $50,000. Defence in depth layers controls generally; it would suit hardening against varied attack vectors, not repairing one broken dual-authorisation rule.
- ✗
Accountability; log all approvals and audit monthly
Why it's wrong here
Logging and monthly auditing only detect the bypass after the fact; they do not restore the requirement that sales and finance each approve, so the single-approver path persists. Accountability logging is the right control when you need non-repudiation and traceability of actions already correctly authorised.
- ✗
Least privilege; reduce the transaction limit to $5,000
Why it's wrong here
Lowering the threshold to $5,000 still permits one manager to approve alone from the trusted IP, so dual authorisation remains absent above the new limit. Least privilege restricts each account to the minimum access needed; it applies to rights assignment, not to enforcing two-person approval on a transaction.
Go deeper
Related to this question
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?
medium- ✓ A.Separation of duties
- B.Defense in depth
- C.Least privilege
- D.Need-to-know
Why A: Separation of duties (SoD) requires that no single individual controls all parts of a critical transaction or process. In this scenario, one employee can both approve purchase orders and receive the goods, meaning they could create a fictitious vendor, approve the payment, and confirm receipt of goods that never arrived — a classic fraud vector. SoD mandates that these two functions be split between different people so that collusion is required to commit fraud.
Variation 2. An organization implements a rule that an employee cannot approve their own expenses. This is an example of which security principle?
easy- A.Least privilege
- ✓ B.Separation of duties
- C.Defense in depth
- D.Accountability
Why B: Correct: B - Separation of duties. Separation of duties prevents a single individual from having conflicting roles. Option A is wrong because least privilege limits access to only necessary resources. Option C is wrong because defense in depth uses multiple layers. Option D is wrong because accountability tracks actions to individuals.
Variation 3. A company implements a policy that requires two employees to approve any financial transaction over $10,000. Which security principle is being applied?
easy- A.Need to know
- B.Defense in depth
- C.Least privilege
- ✓ D.Separation of duties
Why D: Separation of duties (SoD) requires that a sensitive task be divided among multiple people so that no single individual can complete it alone. Requiring two employees to approve any financial transaction over $10,000 is a classic SoD control that prevents fraud and errors by ensuring one person cannot unilaterally authorize a payment.
Variation 4. A security policy requires that all changes to production systems be approved by a change management board. Which THREE of the following principles best support this requirement?
medium- ✓ A.Non-repudiation
- B.Defense in depth
- ✓ C.Separation of duties
- ✓ D.Accountability
- E.Least privilege
Why A: Separation of duties ensures approval and implementation are done by different people. Accountability ensures actions are traceable. Non-repudiation provides proof of approval. Least privilege and defense in depth are less directly related.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.