SY0-301 · Question #21
A user in the company is in charge of various financial roles but needs to prepare for an upcoming audit. They use the same account to access each financial system. Which of the following security…
The correct answer is D. Separation of duties. Separation of duties (SoD) is a security principle that divides critical tasks and privileges among multiple users or accounts to prevent fraud, errors, and abuse of power. When a single user controls multiple financial systems with one account, there is no check-and-balance…
Question
A user in the company is in charge of various financial roles but needs to prepare for an upcoming audit. They use the same account to access each financial system. Which of the following security controls will MOST likely be implemented within the company?
Options
- AAccount lockout policy
- BAccount password enforcement
- CPassword complexity enabled
- DSeparation of duties
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C10% (2)
- D81% (17)
Explanation
Separation of duties (SoD) is a security principle that divides critical tasks and privileges among multiple users or accounts to prevent fraud, errors, and abuse of power. When a single user controls multiple financial systems with one account, there is no check-and-balance mechanism-one person could manipulate records and cover their tracks. An audit would flag this as a risk and require SoD to be implemented, meaning distinct roles (e.g., approving payments vs. recording transactions) must be handled by separate accounts or individuals. The other options-account lockout, password enforcement, and password complexity-are general authentication controls that do not address the core risk of one person having unchecked access to multiple financial functions.
Topics
Community Discussion
No community discussion yet for this question.