Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?

⚠ Common exam trap

The trap here is choosing least privilege alone, when least privilege governs how much access a user has rather than preventing one person from holding two conflicting duties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties and role-based access control with lifecycle management

The requirement that one employee cannot both initiate and approve a transfer is the classic definition of separation of duties, which splits a sensitive process across multiple people. Automatically revoking or adjusting rights when an employee changes departments reflects role-based access control combined with lifecycle management, where access follows the current role rather than persisting indefinitely. Applying both principles together satisfies the firm's objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Zero trust and continuous authentication

    Why it's wrong here

    Zero trust removes implicit trust based on network location, and continuous authentication revalidates identity over time. These concepts improve verification but do not by themselves forbid a single user from holding two conflicting duties. They also do not describe tying permissions to roles and automatically revoking them upon a department change, so they do not fully match the scenario.

  • ✓

    Separation of duties and role-based access control with lifecycle management

    Why this is correct

    Separation of duties ensures that no single individual controls both initiating and approving a sensitive transaction, directly matching the transfer requirement. Pairing this with role-based access control and lifecycle management means rights are tied to roles and updated automatically when an employee changes departments, which satisfies the revocation requirement. Together these principles address both stated objectives.

  • ✗

    Defense in depth and mandatory access control

    Why it's wrong here

    Defense in depth layers multiple controls, and mandatory access control enforces system-assigned labels, but neither specifically prevents one employee from both initiating and approving a transfer. MAC governs access by classification and clearance rather than by conflicting job duties. This combination does not describe the automatic rights adjustment on department change that the scenario requires.

  • ✗

    Least privilege and need to know

    Why it's wrong here

    Least privilege limits users to the minimum access required for their duties, and need to know restricts access to specific information. While both are valuable, neither inherently prevents one person from holding two conflicting duties such as initiating and approving a transfer. These principles address scope of access, not the separation of incompatible functions or automatic rights adjustment on role change.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.