CAS-002 · Question #40
Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:
The correct answer is A. Separation of duties. Separation of Duties is the security principle that divides critical functions among multiple people so no single individual has end-to-end control over a sensitive process. Requiring the systems administrator to be absent during an audit of systems they manage ensures the…
Question
Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:
Options
- ASeparation of duties.
- BMandatory vacation.
- CNon-disclosure agreement.
- DLeast privilege.
How the community answered
(33 responses)- A88% (29)
- B3% (1)
- C3% (1)
- D6% (2)
Explanation
Separation of Duties is the security principle that divides critical functions among multiple people so no single individual has end-to-end control over a sensitive process. Requiring the systems administrator to be absent during an audit of systems they manage ensures the auditor can conduct an independent, unbiased review without the risk of the administrator concealing misconfigurations, policy violations, or unauthorized changes. This preserves the integrity of the audit process. Least privilege (Option D) restricts access rights, mandatory vacation (Option B) detects fraud through coverage, and an NDA (Option C) is a confidentiality agreement - none of these describe the principle of dividing oversight responsibilities.
Topics
Community Discussion
No community discussion yet for this question.