Courseiva
Access Controls →hardMultiple Select

SSCP Access Controls Practice Question

During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?

⚠ Common exam trap

SSCP often tests the overlap between least privilege and separation of duties — candidates pick only one, but the question asks for TWO principles, and both are directly violated by mutually exclusive role assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

Option B (Least privilege) is correct because assigning a user to two mutually exclusive roles grants them more permissions than their job function requires, violating the principle that users should receive only the minimum access necessary to perform their duties. Option C (Separation of duties) is correct because mutually exclusive roles are specifically designed to prevent one person from holding conflicting responsibilities (e.g., initiating and approving a transaction), and assigning both to a single user directly defeats that control. Option A (Role hierarchy) is not necessarily violated, since a hierarchy merely organizes roles by inheritance and does not inherently prohibit holding two roles. Option D (Mandatory access control) is unrelated, as MAC relies on system-enforced labels and clearances rather than conflicting role assignments. Option E (Accountability) concerns traceability of actions to an individual, which is not directly breached by holding two mutually exclusive roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role hierarchy

    Why it's wrong here

    A role hierarchy merely inherits permissions upward through senior roles; it does not forbid one user holding two conflicting roles. Separation of duties and least privilege are breached. Role hierarchy would be relevant if the issue were inherited permissions cascading from a senior role, not mutually exclusive assignments.

  • ✓

    Least privilege

    Why this is correct

    Holding two mutually exclusive roles grants access beyond what either role alone requires for the user's duties. Least privilege is violated because the accumulated permissions exceed the minimum necessary to perform the assigned job function.

  • ✓

    Separation of duties

    Why this is correct

    Assigning one user to two mutually exclusive roles breaches separation of duties, which requires splitting critical tasks so no single person controls an entire process end to end. The conflicting role combination grants excessive, unchecked privileges, directly violating the stem's mutual-exclusivity constraint and enabling fraud or error without detection.

  • ✗

    Mandatory access control

    Why it's wrong here

    Mandatory access control enforces labels and clearances rather than role membership, so conflicting role assignment breaches separation of duties and least privilege instead. It tempts because MAC also prevents toxic combinations, and it would be correct where classification labels, not job roles, govern access decisions.

  • ✗

    Accountability

    Why it's wrong here

    Accountability assigns actions to a named individual, so a role clash does not breach it; separation of duties and least privilege are the violated principles. It tempts because audit trails do track who did what, and accountability would be the answer if the finding were unattributable activity rather than conflicting role assignment.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.