SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses a financial accounting system where the employee who creates a purchase order cannot also approve it. This policy is designed to prevent a single individual from committing fraud by both initiating and approving a transaction. Which security principle does this practice primarily implement?
⚠ Common exam trap
Many exam-takers confuse separation of duties with least privilege, but least privilege limits the scope of permissions while separation of duties divides critical tasks to prevent a single point of failure or fraud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separation of duties
The practice of requiring different individuals to create and approve purchase orders directly implements the separation of duties principle. This security control ensures that no single person has complete control over a sensitive financial transaction, thereby reducing the risk of fraud or error. In the context of identity and access management, separation of duties enforces that conflicting tasks are assigned to different users to prevent abuse of privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege dictates that users, processes, and applications should be granted only the minimum necessary permissions to perform their specific functions and nothing more. While crucial for security by limiting the potential impact of a compromise, this principle focuses on the extent of access for a single entity rather than the distribution of tasks among multiple entities. It does not inherently address the division of critical, incompatible functions across different individuals to prevent a single point of failure or malicious activity.
When this WOULD be correct
In a scenario where a company restricts a user's access to only the specific files needed for their job, such as a customer service representative only having read access to customer records and no access to financial data, the principle of least privilege would be the correct answer.
- ✓
Separation of duties
Why this is correct
Separation of duties is a critical control in financial systems, ensuring that no single individual possesses all the necessary permissions to complete a high-risk transaction or process from start to finish. For instance, the person who approves a payment should not be the same person who initiates the payment or reconciles the bank statement. This distribution of incompatible privileges across multiple employees significantly mitigates the risk of fraud, errors, and insider threats by requiring collusion to bypass controls.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a strategy that employs multiple, overlapping security controls to protect assets, so if one control fails, another is in place to prevent or detect an attack. This approach involves various layers such as physical security, network security (firewalls, IDS/IPS), application security, and data encryption. While vital for creating a robust security posture against external and internal threats, it focuses on the resilience of security mechanisms rather than the organizational structure of job roles and responsibilities to prevent internal fraud or error.
When this WOULD be correct
An exam question might ask: 'A company implements firewalls, intrusion detection, antivirus, and employee training to protect its network. Which security principle does this illustrate?' In that context, defense in depth would be correct because it describes multiple layers of security controls.
- ✗
Zero Trust
Why it's wrong here
Zero Trust is a security model that operates on the principle of "never trust, always verify," regardless of whether the user or device is inside or outside the network perimeter. It mandates explicit verification for every access request, continuous monitoring, and adherence to least privilege access. While Zero Trust enhances overall security posture by reducing implicit trust, its primary focus is on access validation and continuous authentication, not on the architectural design of distributing incompatible job functions among different personnel within a system.
When this WOULD be correct
A question that asks: 'A company implements a policy where all network access requests must be authenticated and authorized regardless of whether they originate from inside or outside the corporate network. Which security principle does this describe?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Separation of dutiesCorrect answer▾
Why this is correct
Separation of duties is a critical control in financial systems, ensuring that no single individual possesses all the necessary permissions to complete a high-risk transaction or process from start to finish. For instance, the person who approves a payment should not be the same person who initiates the payment or reconciles the bank statement. This distribution of incompatible privileges across multiple employees significantly mitigates the risk of fraud, errors, and insider threats by requiring collusion to bypass controls.
✗Least privilegeWrong answer — click to see why▾
Why this is wrong here
The policy prevents the same person from both creating and approving a purchase order, which is a classic example of separation of duties, not least privilege. Least privilege would limit access rights to only what is necessary for a role, but it does not address the conflict of interest between initiating and approving transactions.
★ When this WOULD be the correct answer
In a scenario where a company restricts a user's access to only the specific files needed for their job, such as a customer service representative only having read access to customer records and no access to financial data, the principle of least privilege would be the correct answer.
Why candidates choose this
Candidates may confuse least privilege with separation of duties because both involve restricting user actions, but least privilege focuses on minimal access rights, while separation of duties focuses on dividing critical tasks among multiple people to prevent fraud.
✗Defense in depthWrong answer — click to see why▾
Why this is wrong here
Defense in depth is a layered security strategy using multiple controls, not a principle that separates conflicting duties to prevent fraud. The question specifically asks about preventing a single individual from both initiating and approving a transaction, which is the definition of separation of duties.
★ When this WOULD be the correct answer
An exam question might ask: 'A company implements firewalls, intrusion detection, antivirus, and employee training to protect its network. Which security principle does this illustrate?' In that context, defense in depth would be correct because it describes multiple layers of security controls.
Why candidates choose this
Candidates may confuse 'defense in depth' with any security practice that involves multiple controls, mistakenly thinking that separating duties is a form of layered defense, rather than recognizing it as a distinct principle of internal control.
✗Zero TrustWrong answer — click to see why▾
Why this is wrong here
Zero Trust is a security model that assumes no implicit trust and continuously verifies every access request, but it does not specifically address the separation of conflicting duties like creating and approving purchase orders.
★ When this WOULD be the correct answer
A question that asks: 'A company implements a policy where all network access requests must be authenticated and authorized regardless of whether they originate from inside or outside the corporate network. Which security principle does this describe?'
Why candidates choose this
Candidates may confuse Zero Trust with any security control that prevents fraud, not realizing that Zero Trust focuses on access verification rather than role-based task separation.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Accounting
Accounting in IT identity and access management is the process of tracking and logging what authenticated users do on a system or network.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.