hardMultiple Choice
SSCP Practice Question: A company has a policy requiring segregation of…
A company has a policy requiring segregation of duties (SoD) for financial transactions. Which scenario represents a violation of this principle?
⚠ Common exam trap
SSCP often tests the misconception that any shared responsibility is an SoD violation, when in fact SoD is violated only when one person can both execute and conceal a transaction without independent oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The finance officer approves invoices and also reconciles the bank statements
Segregation of duties requires that no single individual controls all aspects of a transaction, especially those involving financial assets. Having the same finance officer both approve invoices and reconcile bank statements means one person can initiate and conceal a fraudulent payment, which is a classic SoD violation. The other scenarios either separate duties or add independent review.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system administrator performs backups, and the security officer reviews audit logs
Why it's wrong here
Backups by the administrator and independent log review by the security officer separate operational duties from monitoring duties, so no SoD violation exists. It is tempting because both roles touch systems, but SoD is violated only when one individual controls two conflicting phases of a transaction, such as initiation and approval.
- ✓
The finance officer approves invoices and also reconciles the bank statements
Why this is correct
Segregation of duties requires that one person cannot both authorise a transaction and verify it. Approving invoices and reconciling the resulting bank statements gives the finance officer control over both sides, enabling concealment of fraud.
- ✗
Two managers must each approve any expenditure over $10,000
Why it's wrong here
Requiring two managers to approve expenditure over $10,000 enforces dual control, which is a SoD control rather than a violation. It is tempting because dual authorisation sounds like the opposite of SoD, but SoD is breached when one person holds both the ability to initiate and to approve or record a transaction.
- ✗
The purchasing manager creates purchase orders, and the accounts payable clerk processes payments
Why it's wrong here
The purchasing manager raising orders while a separate clerk processes payments splits initiation from disbursement, which satisfies segregation of duties rather than breaching it. It is tempting because two people touch the transaction, and it would be a violation only if one person both created and paid the same order.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.