Courseiva

SSCP Security Operations and Administration Practice Question

A financial services firm is implementing role-based access control for its trading platform. An auditor finds that several traders can approve their own trades in addition to executing them. Which principle is being violated, and which control should the security administrator implement to remediate the finding?

⚠ Common exam trap

A common mix-up: candidates confuse least privilege with separation of duties when a user has two legitimate but conflicting business functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Separation of duties; enforce distinct roles so the trade executor cannot also approve the same transaction.

The auditor observed that the same individual can execute and approve a trade, which is a classic separation of duties violation. Separation of duties ensures that critical tasks are divided among multiple people so that no single person can complete a sensitive transaction alone. Implementing mutually exclusive roles that separate execution from approval directly remediates the finding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Separation of duties; enforce distinct roles so the trade executor cannot also approve the same transaction.

    Why this is correct

    Separation of duties requires that no single individual controls all parts of a critical transaction. Allowing a trader to both execute and approve trades creates an opportunity for fraud or undetected error. Remediation is to define mutually exclusive roles so the approval function is performed by a different authorized person, which directly addresses the conflicting duties observed by the auditor.

  • ✗

    Need to know; restrict traders from viewing market data unrelated to their assigned portfolios.

    Why it's wrong here

    Need to know governs access to information and limits data exposure to what is required for a task. While valuable, it does not prevent a single user from executing and approving the same trade. The auditor's finding concerns conflicting transaction privileges, not excessive data visibility. Applying need-to-know would not remediate the ability to self-approve a trade, so it does not address the actual control gap.

  • ✗

    Least privilege; implement just-in-time privileged access with approval workflows.

    Why it's wrong here

    Least privilege limits users to the minimum access needed for their duties, but the scenario describes a user performing two conflicting functions within the same transaction workflow. Just-in-time access addresses when privileges are granted, not the fundamental conflict of one person executing and approving the same trade. The core issue is the combination of duties, which requires separation of duties rather than time-bound elevation.

  • ✗

    Mandatory access control; classify trades by sensitivity and apply system-enforced labels.

    Why it's wrong here

    Mandatory access control uses labels and clearances to enforce access decisions independent of user discretion, which is more typical of government or military environments. It does not inherently prevent one authorized user from performing two business functions. The finding is about conflicting business duties within a workflow, so separation of duties is the appropriate model rather than label-based access enforcement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.