SSCP Access Controls Practice Question
An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit logging and monitoring of privileged actions
Separation of duties is enforced through role-based access control (assigning conflicting roles to different users), requiring dual authorization for critical actions, and audit logging for accountability. Password complexity and biometrics are authentication, not separation of duties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Audit logging and monitoring of privileged actions
Why this is correct
Logging provides accountability, a key component of separation of duties.
- ✓
Role-based access control with mutually exclusive roles
Why this is correct
RBAC can define conflicting roles that cannot be assigned together.
- ✗
Enforcing complex password policies
Why it's wrong here
Password policies relate to authentication, not separation of duties.
- ✗
Using biometric authentication
Why it's wrong here
Biometrics are for authentication, not separation of duties.
- ✓
Requiring two or more people to approve a transaction
Why this is correct
Dual authorization ensures no single person can complete a critical action.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?
medium- A.Users can share accounts to simplify management
- ✓ B.It prevents users from having conflicting roles that could lead to fraud
- C.It allows users to define their own permissions
- D.It uses system-wide labels to control access
Why B: RBAC naturally supports separation of duties by assigning permissions to roles and ensuring that conflicting roles (e.g., approving and executing payments) are not assigned to the same user. This reduces fraud risk.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.