nerdexam
CompTIA

CAS-001 · Question #268

Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:

The correct answer is A. separation of duties. Separation of duties is the security principle that divides critical tasks and responsibilities among multiple people so no single individual can perform all steps of a sensitive process - particularly reviewing their own work. Requiring the systems administrator to be absent…

Enterprise Security

Question

Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:

Options

  • Aseparation of duties.
  • Bmandatory vacation.
  • Cnon-disclosure agreement.
  • Dleast privilege.

How the community answered

(42 responses)
  • A
    93% (39)
  • C
    2% (1)
  • D
    5% (2)

Explanation

Separation of duties is the security principle that divides critical tasks and responsibilities among multiple people so no single individual can perform all steps of a sensitive process - particularly reviewing their own work. Requiring the systems administrator to be absent during an audit of their own systems prevents them from influencing, concealing, or manipulating audit results, ensuring the audit remains objective and independent. Mandatory vacation (B) is a different control designed to detect fraud by having someone else cover duties. NDA (C) is about confidentiality agreements. Least privilege (D) limits what access a user has, not who can be present for an audit.

Topics

#separation of duties#security policy#audit controls

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice