nerdexam
EC-Council

312-50V9 · Question #429

A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID card access system to…

The correct answer is A. Segregation of duties. Segregation of duties is violated when a single person both grants access and audits that same access, creating an unchecked conflict of interest.

Introduction to Ethical Hacking

Question

A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID card access system to a new server room on campus. The server room will house student enrollment information that is securely backed up to an off-site location. During a meeting with an outside consultant, the Chief Security Officer explains that he is concerned that the existing security controls have not been designed properly. Currently, the Network Administrator is responsible for approving and issuing RFID card access to the server room, as well as reviewing the electronic access logs on a weekly basis. Which of the following is an issue with the situation?

Options

  • ASegregation of duties
  • BUndue influence
  • CLack of experience
  • DInadequate disaster recovery plan

How the community answered

(30 responses)
  • A
    70% (21)
  • B
    20% (6)
  • C
    3% (1)
  • D
    7% (2)

Why each option

Segregation of duties is violated when a single person both grants access and audits that same access, creating an unchecked conflict of interest.

ASegregation of dutiesCorrect

Segregation of duties (SoD) requires that critical tasks - such as provisioning access and reviewing access logs - be divided among different individuals to prevent fraud, error, or abuse. In this scenario, the Network Administrator approves RFID access and also reviews the audit logs that would detect unauthorized access grants, meaning the same person can cover their own tracks. Proper SoD would assign these responsibilities to separate roles or departments.

BUndue influence

Undue influence refers to pressure exerted on a person to act against their will or judgment, which is not described in the scenario.

CLack of experience

Lack of experience is not indicated - the scenario describes a promotion, not a competency gap, and experience is not the identified security control failure.

DInadequate disaster recovery plan

An inadequate disaster recovery plan relates to business continuity for outages or disasters, not to the access control oversight issue described.

Concept tested: Segregation of duties in access control management

Source: https://csrc.nist.gov/glossary/term/separation_of_duty

Topics

#segregation of duties#RFID access control#security controls#privilege management

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice