nerdexam
CompTIA

CAS-002 · Question #40

Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:

The correct answer is A. Separation of duties. Separation of Duties is the security principle that divides critical functions among multiple people so no single individual has end-to-end control over a sensitive process. Requiring the systems administrator to be absent during an audit of systems they manage ensures the…

Enterprise Security

Question

Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:

Options

  • ASeparation of duties.
  • BMandatory vacation.
  • CNon-disclosure agreement.
  • DLeast privilege.

How the community answered

(33 responses)
  • A
    88% (29)
  • B
    3% (1)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Separation of Duties is the security principle that divides critical functions among multiple people so no single individual has end-to-end control over a sensitive process. Requiring the systems administrator to be absent during an audit of systems they manage ensures the auditor can conduct an independent, unbiased review without the risk of the administrator concealing misconfigurations, policy violations, or unauthorized changes. This preserves the integrity of the audit process. Least privilege (Option D) restricts access rights, mandatory vacation (Option B) detects fraud through coverage, and an NDA (Option C) is a confidentiality agreement - none of these describe the principle of dividing oversight responsibilities.

Topics

#separation of duties#security policy#auditing#access control

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice