nerdexam
CompTIA

CAS-001 · Question #41

The Chief Information Security Officer (CISO) is researching ways to reduce the risk associated with administrative access of six IT staff members while enforcing separation of duties. In the case…

The correct answer is B. Require role-based security on primary role, and only provide access to secondary roles on a. The requirement has two competing needs: enforce separation of duties (no one person has all access by default) AND allow cross-coverage when staff are absent. Option B satisfies both by assigning each user a primary role (separation of duties) while enabling temporary…

Enterprise Security

Question

The Chief Information Security Officer (CISO) is researching ways to reduce the risk associated with administrative access of six IT staff members while enforcing separation of duties. In the case where an IT staff member is absent, each staff member should be able to perform all the necessary duties of their IT co-workers. Which of the following policies should the CISO implement to reduce the risk?

Options

  • ARequire the use of an unprivileged account, and a second shared account only for administrative
  • BRequire role-based security on primary role, and only provide access to secondary roles on a
  • CRequire separation of duties ensuring no single administrator has access to all systems.
  • DRequire on-going auditing of administrative activities, and evaluate against risk-based metrics.

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    69% (29)
  • C
    19% (8)
  • D
    7% (3)

Explanation

The requirement has two competing needs: enforce separation of duties (no one person has all access by default) AND allow cross-coverage when staff are absent. Option B satisfies both by assigning each user a primary role (separation of duties) while enabling temporary secondary role access on a need basis (cross-coverage). Option A is wrong because shared accounts destroy accountability and non-repudiation. Option C prevents any single admin from accessing all systems but does not provide a mechanism for cross-coverage when someone is absent. Option D addresses detection via auditing but does not reduce access risk or provide cross-coverage.

Topics

#role-based access control#separation of duties#privileged access management#administrative security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice