SSCP Access Controls Practice Question
A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?
⚠ Common exam trap
The trap here is choosing least privilege alone, when least privilege governs how much access a user has rather than preventing one person from holding two conflicting duties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties and role-based access control with lifecycle management
The requirement that one employee cannot both initiate and approve a transfer is the classic definition of separation of duties, which splits a sensitive process across multiple people. Automatically revoking or adjusting rights when an employee changes departments reflects role-based access control combined with lifecycle management, where access follows the current role rather than persisting indefinitely. Applying both principles together satisfies the firm's objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Zero trust and continuous authentication
Why it's wrong here
Zero trust removes implicit trust based on network location, and continuous authentication revalidates identity over time. These concepts improve verification but do not by themselves forbid a single user from holding two conflicting duties. They also do not describe tying permissions to roles and automatically revoking them upon a department change, so they do not fully match the scenario.
- ✓
Separation of duties and role-based access control with lifecycle management
Why this is correct
Separation of duties ensures that no single individual controls both initiating and approving a sensitive transaction, directly matching the transfer requirement. Pairing this with role-based access control and lifecycle management means rights are tied to roles and updated automatically when an employee changes departments, which satisfies the revocation requirement. Together these principles address both stated objectives.
- ✗
Defense in depth and mandatory access control
Why it's wrong here
Defense in depth layers multiple controls, and mandatory access control enforces system-assigned labels, but neither specifically prevents one employee from both initiating and approving a transfer. MAC governs access by classification and clearance rather than by conflicting job duties. This combination does not describe the automatic rights adjustment on department change that the scenario requires.
- ✗
Least privilege and need to know
Why it's wrong here
Least privilege limits users to the minimum access required for their duties, and need to know restricts access to specific information. While both are valuable, neither inherently prevents one person from holding two conflicting duties such as initiating and approving a transfer. These principles address scope of access, not the separation of incompatible functions or automatic rights adjustment on role change.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.