CISSP Identity and Access Management Practice Question
A security policy requires that a user cannot have both the ability to create purchase orders and approve invoices. This is an example of:
⚠ Common exam trap
CISSP often tests the confusion between separation of duties and least privilege, as both involve limiting access, but SoD specifically addresses conflicting responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
Separation of duties is a principle that prevents a single individual from having control over all aspects of a critical process. In this case, requiring that a user cannot both create purchase orders and approve invoices ensures that no single person can initiate and authorize a transaction, reducing the risk of fraud or error. This is a classic example of separation of duties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties
Why this is correct
Separation of duties (SoD) is a critical preventative control designed to mitigate the risk of fraud, error, or misuse by ensuring that no single individual possesses all the necessary permissions or capabilities to complete a critical or sensitive transaction end-to-end. This policy directly addresses the requirement that a user cannot have both conflicting responsibilities, thereby preventing a single point of failure or malicious action. It mandates that distinct, high-risk tasks are divided among multiple people.
- ✗
Need-to-know
Why it's wrong here
Need-to-know is an access control principle that dictates individuals should only be granted access to information or resources strictly necessary for them to perform their assigned job functions. While it restricts overall data exposure by limiting access to relevant data, it does not inherently prevent a user from being assigned two distinct operational privileges that, while individually necessary, create a conflict when held concurrently by the same person, which is the specific focus of the question.
- ✗
Least privilege
Why it's wrong here
Least privilege is a fundamental security principle that ensures users, programs, or processes are granted only the minimum necessary rights and permissions to perform their authorized tasks and nothing more. Although it limits the scope of potential damage by preventing excessive rights, it does not specifically address the scenario where two individually minimal but conflicting privileges might be assigned to the same user, which is precisely what separation of duties aims to prevent.
- ✗
Job rotation
Why it's wrong here
Job rotation is an administrative control that involves periodically moving employees among different roles or responsibilities within an organization. This practice serves as a detective control to uncover potential fraud or errors and provides cross-training benefits, but it does not directly prevent a single user from possessing two conflicting permissions or duties at any given moment, which is the immediate concern of the security policy requiring specific duty separation.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.