nerdexam
EXIN

BIMF.EN · Question #85

An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

The correct answer is B. No. Having access to an application you've never used does not constitute an information security incident - it is a potential access control weakness or policy misconfiguration, but no security event has actually occurred. An information security incident requires that…

Information Management Introduction

Question

An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

Options

  • AYes
  • BNo

How the community answered

(23 responses)
  • A
    22% (5)
  • B
    78% (18)

Explanation

Having access to an application you've never used does not constitute an information security incident - it is a potential access control weakness or policy misconfiguration, but no security event has actually occurred. An information security incident requires that confidentiality, integrity, or availability has been compromised, or that a security policy has been actively violated with some adverse effect. Simply possessing access rights, even excessive ones, is a vulnerability to be reviewed and remediated through access management processes, not an incident to be reported.

Why A is wrong: Discovering unused access rights triggers an access review, not an incident response. If the employee had exploited that access to view restricted data, that would be an incident - but awareness alone causes no harm.

Memory tip: Use the "CIA + action" rule - a true security incident must affect Confidentiality, Integrity, or Availability through some action. Unused access is a gap in least-privilege controls, not an incident.

Topics

#information security#access control#security incident#authorization

Community Discussion

No community discussion yet for this question.

Full BIMF.EN Practice