SSCP Security Operations and Administration Practice Question
A financial services firm is implementing role-based access control for its trading platform. An auditor finds that several traders can approve their own trades in addition to executing them. Which principle is being violated, and which control should the security administrator implement to remediate the finding?
⚠ Common exam trap
A common mix-up: candidates confuse least privilege with separation of duties when a user has two legitimate but conflicting business functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties; enforce distinct roles so the trade executor cannot also approve the same transaction.
The auditor observed that the same individual can execute and approve a trade, which is a classic separation of duties violation. Separation of duties ensures that critical tasks are divided among multiple people so that no single person can complete a sensitive transaction alone. Implementing mutually exclusive roles that separate execution from approval directly remediates the finding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Separation of duties; enforce distinct roles so the trade executor cannot also approve the same transaction.
Why this is correct
Separation of duties requires that no single individual controls all parts of a critical transaction. Allowing a trader to both execute and approve trades creates an opportunity for fraud or undetected error. Remediation is to define mutually exclusive roles so the approval function is performed by a different authorized person, which directly addresses the conflicting duties observed by the auditor.
- ✗
Need to know; restrict traders from viewing market data unrelated to their assigned portfolios.
Why it's wrong here
Need to know governs access to information and limits data exposure to what is required for a task. While valuable, it does not prevent a single user from executing and approving the same trade. The auditor's finding concerns conflicting transaction privileges, not excessive data visibility. Applying need-to-know would not remediate the ability to self-approve a trade, so it does not address the actual control gap.
- ✗
Least privilege; implement just-in-time privileged access with approval workflows.
Why it's wrong here
Least privilege limits users to the minimum access needed for their duties, but the scenario describes a user performing two conflicting functions within the same transaction workflow. Just-in-time access addresses when privileges are granted, not the fundamental conflict of one person executing and approving the same trade. The core issue is the combination of duties, which requires separation of duties rather than time-bound elevation.
- ✗
Mandatory access control; classify trades by sensitivity and apply system-enforced labels.
Why it's wrong here
Mandatory access control uses labels and clearances to enforce access decisions independent of user discretion, which is more typical of government or military environments. It does not inherently prevent one authorized user from performing two business functions. The finding is about conflicting business duties within a workflow, so separation of duties is the appropriate model rather than label-based access enforcement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.