CAS-001 · Question #239
An administrator is reviewing a recent security audit and determines that two users in finance also have access to the human resource data. One of those users fills in for any HR employees on…
The correct answer is D. Least privilege. The principle of least privilege states that users should be granted only the minimum access rights necessary to perform their specific job functions - and nothing more. The finance-only employee has no business need to access HR data; that access is excess privilege beyond…
Question
An administrator is reviewing a recent security audit and determines that two users in finance also have access to the human resource data. One of those users fills in for any HR employees on vacation, the other user only works in finance. Which of the following policies is being violated by the finance user according to the audit results?
Options
- AMandatory vacation
- BNon-disclosure
- CJob rotation
- DLeast privilege
How the community answered
(23 responses)- B4% (1)
- C9% (2)
- D87% (20)
Explanation
The principle of least privilege states that users should be granted only the minimum access rights necessary to perform their specific job functions - and nothing more. The finance-only employee has no business need to access HR data; that access is excess privilege beyond what their role requires. This is a direct violation of least privilege. The audit correctly flags this user (but not the HR fill-in, whose dual access is business-justified). Option A (mandatory vacation) ensures employees take leave to detect fraud but is unrelated to access rights. Option B (non-disclosure) governs information sharing, not access control. Option C (job rotation) involves moving employees through different roles to cross-train and detect fraud, but does not address having inappropriate standing access.
Topics
Community Discussion
No community discussion yet for this question.