Courseiva
Access ControlsmediumMultiple SelectObjective-mapped

SSCP Access Controls Practice Question

An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Audit logging and monitoring of privileged actions

Separation of duties is enforced through role-based access control (assigning conflicting roles to different users), requiring dual authorization for critical actions, and audit logging for accountability. Password complexity and biometrics are authentication, not separation of duties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Audit logging and monitoring of privileged actions

    Why this is correct

    Logging provides accountability, a key component of separation of duties.

  • Role-based access control with mutually exclusive roles

    Why this is correct

    RBAC can define conflicting roles that cannot be assigned together.

  • Enforcing complex password policies

    Why it's wrong here

    Password policies relate to authentication, not separation of duties.

  • Using biometric authentication

    Why it's wrong here

    Biometrics are for authentication, not separation of duties.

  • Requiring two or more people to approve a transaction

    Why this is correct

    Dual authorization ensures no single person can complete a critical action.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?

medium
  • A.Users can share accounts to simplify management
  • B.It prevents users from having conflicting roles that could lead to fraud
  • C.It allows users to define their own permissions
  • D.It uses system-wide labels to control access

Why B: RBAC naturally supports separation of duties by assigning permissions to roles and ensuring that conflicting roles (e.g., approving and executing payments) are not assigned to the same user. This reduces fraud risk.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.