nerdexam
EC-Council

212-89 · Question #87

Eric works as a system administrator in ABC organization. He granted privileged users with unlimited permissions to access the systems. These privileged users can misuse their rights unintentionally…

The correct answer is C. Do not enable the default administrative accounts to ensure accountability. The guideline that helps incident handlers to eradicate insider attacks by privileged users is to ensure accountability by not enabling default administrative accounts. Instead, organizations should require administrators and privileged users to use individual accounts that can…

Incident Handling and Response Process

Question

Eric works as a system administrator in ABC organization. He granted privileged users with unlimited permissions to access the systems. These privileged users can misuse their rights unintentionally or maliciously or attackers can trick them to perform malicious activities. Which of the following guidelines helps incident handlers to eradicate insider attacks by privileged users?

Options

  • ADo not use encryption methods to prevent administrators and privileged users from accessing
  • BDo not control the access to administrators and privileged users
  • CDo not enable the default administrative accounts to ensure accountability
  • DDo not allow administrators to use unique accounts during the installation process

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    81% (22)
  • D
    4% (1)

Explanation

The guideline that helps incident handlers to eradicate insider attacks by privileged users is to ensure accountability by not enabling default administrative accounts. Instead, organizations should require administrators and privileged users to use individual accounts that can be audited and traced back to specific actions and users. This practice enhances security by ensuring that all actions taken on the system can be attributed to individual users, reducing the risk of misuse of privileges and making it easier to identify the source of malicious activities or policy violations. The other options listed either present insecure practices or misunderstandings of security protocols that would not help in eradicating insider attacks.

Topics

#insider threats#privileged users#account management#eradication

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice