nerdexam
CompTIA

CAS-003 · Question #751

When of the following is the BEST reason to implement a separation of duties policy?

The correct answer is A. It minimizes the risk of Dos due to continuous monitoring. This answer key contains an error. The correct answer is C. Separation of duties (SoD) is a security control that divides critical tasks among multiple individuals so that no single person has enough access or authority to commit fraud undetected. For example, the person who…

Risk Management

Question

When of the following is the BEST reason to implement a separation of duties policy?

Options

  • AIt minimizes the risk of Dos due to continuous monitoring.
  • BIt eliminates the need to enforce least privilege by logging all actions.
  • CIt increases the level of difficulty for a single employee to perpetrate fraud.
  • Dit removes barriers to collusion and collaboration between business units.

How the community answered

(17 responses)
  • A
    94% (16)
  • B
    6% (1)

Explanation

This answer key contains an error. The correct answer is C. Separation of duties (SoD) is a security control that divides critical tasks among multiple individuals so that no single person has enough access or authority to commit fraud undetected. For example, the person who approves a payment should not also be the person who processes it. Option A is incorrect - SoD has nothing to do with preventing denial-of-service attacks or continuous monitoring. Option B is incorrect - SoD does not eliminate least privilege; both controls are used together. Option D is the opposite of what SoD does - it reduces collaboration barriers for potentially malicious collusion, not removes them. Option C correctly identifies the primary purpose of SoD: making it significantly harder for any one employee to act maliciously alone.

Topics

#separation of duties#fraud prevention#access control#security policy

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice