SSCP Access Controls Practice Question
During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?
⚠ Common exam trap
SSCP often tests the overlap between least privilege and separation of duties — candidates pick only one, but the question asks for TWO principles, and both are directly violated by mutually exclusive role assignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Option B (Least privilege) is correct because assigning a user to two mutually exclusive roles grants them more permissions than their job function requires, violating the principle that users should receive only the minimum access necessary to perform their duties. Option C (Separation of duties) is correct because mutually exclusive roles are specifically designed to prevent one person from holding conflicting responsibilities (e.g., initiating and approving a transaction), and assigning both to a single user directly defeats that control. Option A (Role hierarchy) is not necessarily violated, since a hierarchy merely organizes roles by inheritance and does not inherently prohibit holding two roles. Option D (Mandatory access control) is unrelated, as MAC relies on system-enforced labels and clearances rather than conflicting role assignments. Option E (Accountability) concerns traceability of actions to an individual, which is not directly breached by holding two mutually exclusive roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role hierarchy
Why it's wrong here
A role hierarchy merely inherits permissions upward through senior roles; it does not forbid one user holding two conflicting roles. Separation of duties and least privilege are breached. Role hierarchy would be relevant if the issue were inherited permissions cascading from a senior role, not mutually exclusive assignments.
- ✓
Least privilege
Why this is correct
Holding two mutually exclusive roles grants access beyond what either role alone requires for the user's duties. Least privilege is violated because the accumulated permissions exceed the minimum necessary to perform the assigned job function.
- ✓
Separation of duties
Why this is correct
Assigning one user to two mutually exclusive roles breaches separation of duties, which requires splitting critical tasks so no single person controls an entire process end to end. The conflicting role combination grants excessive, unchecked privileges, directly violating the stem's mutual-exclusivity constraint and enabling fraud or error without detection.
- ✗
Mandatory access control
Why it's wrong here
Mandatory access control enforces labels and clearances rather than role membership, so conflicting role assignment breaches separation of duties and least privilege instead. It tempts because MAC also prevents toxic combinations, and it would be correct where classification labels, not job roles, govern access decisions.
- ✗
Accountability
Why it's wrong here
Accountability assigns actions to a named individual, so a role clash does not breach it; separation of duties and least privilege are the violated principles. It tempts because audit trails do track who did what, and accountability would be the answer if the finding were unattributable activity rather than conflicting role assignment.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.