nerdexam
CompTIA

CAS-002 · Question #83

After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds that it is impossible…

The correct answer is A. Implement an enforceable change management system. C. Enable user level auditing on all servers. Implementing a change management system paired with user-level server auditing creates both a pre-approval control gate and a forensic record to attribute administrative actions.

Enterprise Security

Question

After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds that it is impossible to know who did the update since five different people have administrative access. How should the IT manager increase accountability to prevent this situation from reoccurring? (Select TWO).

Options

  • AImplement an enforceable change management system.
  • BImplement a software development life cycle policy.
  • CEnable user level auditing on all servers.
  • DImplement a federated identity management system.
  • EConfigure automatic updates on all servers.

How the community answered

(44 responses)
  • A
    80% (35)
  • B
    2% (1)
  • D
    7% (3)
  • E
    11% (5)

Why each option

Implementing a change management system paired with user-level server auditing creates both a pre-approval control gate and a forensic record to attribute administrative actions.

AImplement an enforceable change management system.Correct

An enforceable change management system requires changes to be requested, approved, documented, and linked to a responsible party before execution, creating an authoritative record that identifies who was authorized to perform each change.

BImplement a software development life cycle policy.

A software development life cycle policy governs how software is built and released, not who performs live operational changes on production servers.

CEnable user level auditing on all servers.Correct

User-level auditing on servers captures the specific account, timestamp, and action for every administrative operation, providing the forensic trail needed to identify exactly which individual performed a given change after the fact.

DImplement a federated identity management system.

Federated identity management consolidates authentication across systems but does not enforce change approval workflows or generate server-level activity audit logs.

EConfigure automatic updates on all servers.

Automatic updates remove human involvement entirely and produce uncontrolled, unattributed changes - directly worsening the accountability problem.

Concept tested: Change management and server auditing for accountability

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#change management#user auditing#accountability#administrative access

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice