Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company uses a financial accounting system where the employee who creates a purchase order cannot also approve it. This policy is designed to prevent a single individual from committing fraud by both initiating and approving a transaction. Which security principle does this practice primarily implement?

⚠ Common exam trap

Many exam-takers confuse separation of duties with least privilege, but least privilege limits the scope of permissions while separation of duties divides critical tasks to prevent a single point of failure or fraud.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Separation of duties

The practice of requiring different individuals to create and approve purchase orders directly implements the separation of duties principle. This security control ensures that no single person has complete control over a sensitive financial transaction, thereby reducing the risk of fraud or error. In the context of identity and access management, separation of duties enforces that conflicting tasks are assigned to different users to prevent abuse of privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Least privilege

    Why it's wrong here

    Least privilege dictates that users, processes, and applications should be granted only the minimum necessary permissions to perform their specific functions and nothing more. While crucial for security by limiting the potential impact of a compromise, this principle focuses on the extent of access for a single entity rather than the distribution of tasks among multiple entities. It does not inherently address the division of critical, incompatible functions across different individuals to prevent a single point of failure or malicious activity.

    When this WOULD be correct

    In a scenario where a company restricts a user's access to only the specific files needed for their job, such as a customer service representative only having read access to customer records and no access to financial data, the principle of least privilege would be the correct answer.

  • Separation of duties

    Why this is correct

    Separation of duties is a critical control in financial systems, ensuring that no single individual possesses all the necessary permissions to complete a high-risk transaction or process from start to finish. For instance, the person who approves a payment should not be the same person who initiates the payment or reconciles the bank statement. This distribution of incompatible privileges across multiple employees significantly mitigates the risk of fraud, errors, and insider threats by requiring collusion to bypass controls.

  • Defense in depth

    Why it's wrong here

    Defense in depth is a strategy that employs multiple, overlapping security controls to protect assets, so if one control fails, another is in place to prevent or detect an attack. This approach involves various layers such as physical security, network security (firewalls, IDS/IPS), application security, and data encryption. While vital for creating a robust security posture against external and internal threats, it focuses on the resilience of security mechanisms rather than the organizational structure of job roles and responsibilities to prevent internal fraud or error.

    When this WOULD be correct

    An exam question might ask: 'A company implements firewalls, intrusion detection, antivirus, and employee training to protect its network. Which security principle does this illustrate?' In that context, defense in depth would be correct because it describes multiple layers of security controls.

  • Zero Trust

    Why it's wrong here

    Zero Trust is a security model that operates on the principle of "never trust, always verify," regardless of whether the user or device is inside or outside the network perimeter. It mandates explicit verification for every access request, continuous monitoring, and adherence to least privilege access. While Zero Trust enhances overall security posture by reducing implicit trust, its primary focus is on access validation and continuous authentication, not on the architectural design of distributing incompatible job functions among different personnel within a system.

    When this WOULD be correct

    A question that asks: 'A company implements a policy where all network access requests must be authenticated and authorized regardless of whether they originate from inside or outside the corporate network. Which security principle does this describe?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Separation of dutiesCorrect answer

Why this is correct

Separation of duties is a critical control in financial systems, ensuring that no single individual possesses all the necessary permissions to complete a high-risk transaction or process from start to finish. For instance, the person who approves a payment should not be the same person who initiates the payment or reconciles the bank statement. This distribution of incompatible privileges across multiple employees significantly mitigates the risk of fraud, errors, and insider threats by requiring collusion to bypass controls.

Least privilegeWrong answer — click to see why

Why this is wrong here

The policy prevents the same person from both creating and approving a purchase order, which is a classic example of separation of duties, not least privilege. Least privilege would limit access rights to only what is necessary for a role, but it does not address the conflict of interest between initiating and approving transactions.

★ When this WOULD be the correct answer

In a scenario where a company restricts a user's access to only the specific files needed for their job, such as a customer service representative only having read access to customer records and no access to financial data, the principle of least privilege would be the correct answer.

Why candidates choose this

Candidates may confuse least privilege with separation of duties because both involve restricting user actions, but least privilege focuses on minimal access rights, while separation of duties focuses on dividing critical tasks among multiple people to prevent fraud.

Defense in depthWrong answer — click to see why

Why this is wrong here

Defense in depth is a layered security strategy using multiple controls, not a principle that separates conflicting duties to prevent fraud. The question specifically asks about preventing a single individual from both initiating and approving a transaction, which is the definition of separation of duties.

★ When this WOULD be the correct answer

An exam question might ask: 'A company implements firewalls, intrusion detection, antivirus, and employee training to protect its network. Which security principle does this illustrate?' In that context, defense in depth would be correct because it describes multiple layers of security controls.

Why candidates choose this

Candidates may confuse 'defense in depth' with any security practice that involves multiple controls, mistakenly thinking that separating duties is a form of layered defense, rather than recognizing it as a distinct principle of internal control.

Zero TrustWrong answer — click to see why

Why this is wrong here

Zero Trust is a security model that assumes no implicit trust and continuously verifies every access request, but it does not specifically address the separation of conflicting duties like creating and approving purchase orders.

★ When this WOULD be the correct answer

A question that asks: 'A company implements a policy where all network access requests must be authenticated and authorized regardless of whether they originate from inside or outside the corporate network. Which security principle does this describe?'

Why candidates choose this

Candidates may confuse Zero Trust with any security control that prevents fraud, not realizing that Zero Trust focuses on access verification rather than role-based task separation.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.