nerdexam
Palo_Alto_Networks

PCCET · Question #135

Only one manager can get company checks. Only a different manager can sign checks. This example describes which principle?

The correct answer is A. separation of duties. This scenario exemplifies the principle of separation of duties, where critical functions are divided among different individuals to prevent conflicts of interest and reduce the risk of fraud or error.

Submitted by takeshi77· Apr 18, 2026Cybersecurity Foundations

Question

Only one manager can get company checks. Only a different manager can sign checks. This example describes which principle?

Options

  • Aseparation of duties
  • Bauditability
  • Cleast privilege
  • Ddefense in depth

How the community answered

(42 responses)
  • A
    86% (36)
  • B
    5% (2)
  • C
    2% (1)
  • D
    7% (3)

Why each option

This scenario exemplifies the principle of separation of duties, where critical functions are divided among different individuals to prevent conflicts of interest and reduce the risk of fraud or error.

Aseparation of dutiesCorrect

Separation of duties is a security principle that divides critical functions and responsibilities among different individuals to prevent a single person from having excessive control that could lead to fraud or error. In this case, one manager's ability to get checks is separated from another manager's ability to sign them, creating a necessary control.

Bauditability

Auditability refers to the ability to examine and verify records and processes, which is a consequence of good controls like separation of duties but not the principle itself.

Cleast privilege

Least privilege dictates that users should only be granted the minimum necessary access rights or permissions to perform their job, which is related to access control but not the division of tasks.

Ddefense in depth

Defense in depth involves implementing multiple layers of security controls to protect assets, which is a broader security strategy rather than a specific principle for task division.

Concept tested: Security principles (separation of duties)

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/identity-management-best-practices#enforce-least-privilege-and-separation-of-duties

Topics

#separation of duties#access control#risk management#internal controls

Community Discussion

No community discussion yet for this question.

Full PCCET Practice