nerdexam
EC-Council

712-50 · Question #132

Which represents PROPER separation of duties in the corporate environment?

The correct answer is D. Information Security and Network teams perform two distinct functions. Separation of Duties (SoD) requires that distinct, potentially conflicting functions be assigned to different teams or individuals to prevent fraud, errors, and abuse of privilege. D is correct because Information Security (protecting systems/data) and Networking (managing…

Governance (Policy, Legal & Compliance)

Question

Which represents PROPER separation of duties in the corporate environment?

Options

  • AInformation Security and Identity Access Management teams perform two distinct functions
  • BDevelopers and Network teams both have admin rights on servers
  • CFinance has access to Human Resources data
  • DInformation Security and Network teams perform two distinct functions

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    9% (2)
  • D
    74% (17)

Explanation

Separation of Duties (SoD) requires that distinct, potentially conflicting functions be assigned to different teams or individuals to prevent fraud, errors, and abuse of privilege.

D is correct because Information Security (protecting systems/data) and Networking (managing infrastructure) are two genuinely distinct operational functions with different scopes of responsibility - neither team should control the other's domain, creating a natural check-and-balance.

Why the distractors fail:

  • A - Identity Access Management is a subset of Information Security; they are closely related functions, not truly independent. Placing them together creates overlap rather than true separation.
  • B - Both Developers and Network teams having admin rights on servers is the opposite of SoD - it concentrates privileged access across multiple groups without restriction, increasing risk.
  • C - Finance accessing HR data is a cross-department data access issue, not a demonstration of SoD; it actually violates the principle of least privilege.

Memory tip: Think of SoD as "no one team should be able to do the whole job alone." For the exam, watch for answers where two teams share the same type of power (both have admin rights) or where one function is a subset of another - those are SoD violations, not examples of it.

Topics

#Separation of Duties#Access Control#Governance#Risk Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice