nerdexam
CompTIA

SY0-501 · Question #440

To help prevent one job role from having sufficient access to create, modify, and approve payroll data, which of the following practices should be employed?

The correct answer is D. Separation of duties. Separation of duties is the practice of dividing critical tasks and privileges among multiple individuals or roles to prevent any single person from having complete control over a process. This directly addresses the risk of one job role having excessive access to sensitive…

Submitted by devops_kid· Mar 4, 2026Security program management and oversight

Question

To help prevent one job role from having sufficient access to create, modify, and approve payroll data, which of the following practices should be employed?

Options

  • ALeast privilege
  • BJob rotation
  • CBackground checks
  • DSeparation of duties

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    7% (2)
  • D
    85% (23)

Why each option

Separation of duties is the practice of dividing critical tasks and privileges among multiple individuals or roles to prevent any single person from having complete control over a process. This directly addresses the risk of one job role having excessive access to sensitive functions like payroll management.

ALeast privilege

Least privilege ensures users are granted only the minimum access required to perform their duties, but it doesn't inherently divide a sensitive process among multiple roles to prevent one role from having excessive cumulative control.

BJob rotation

Job rotation involves moving employees between different roles to detect fraud and provide cross-training, but it does not directly prevent a single job role from having complete control over a process at any given time.

CBackground checks

Background checks verify an individual's history and trustworthiness before employment, which is a pre-emptive measure but not a control for distributing operational access or preventing a single role from accumulating excessive privileges.

DSeparation of dutiesCorrect

Separation of duties is a fundamental security control that divides critical functions, such as creating, modifying, and approving payroll, among multiple individuals or job roles. This ensures no single person has sufficient access to execute or conceal fraudulent activities or errors, thereby directly preventing the scenario where one job role can control the entire payroll process.

Concept tested: Separation of duties principle

Source: https://learn.microsoft.com/en-us/microsoft-365/enterprise/security-and-compliance-zero-trust-design?view=o365-worldwide#separation-of-duties

Topics

#separation of duties#access control#least privilege#payroll security

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice