nerdexam
CompTIA

CAS-003 · Question #840

During an audit, an information security analyst discovers accounts that are still assigned to employees who no longer work for the company and new accounts that need to be verified against a list…

The correct answer is C. employment and termination procedures. Auditing stale accounts from terminated employees and unverified new accounts directly informs and validates employment and termination procedures by exposing failures in account provisioning and deprovisioning workflows.

Risk Management

Question

During an audit, an information security analyst discovers accounts that are still assigned to employees who no longer work for the company and new accounts that need to be verified against a list of authorized users. This type of auditing supports the development of:

Options

  • Ainformation classification.
  • Bcontinuous monitoring.
  • Cemployment and termination procedures.
  • Dleast privilege.

How the community answered

(20 responses)
  • A
    5% (1)
  • C
    90% (18)
  • D
    5% (1)

Why each option

Auditing stale accounts from terminated employees and unverified new accounts directly informs and validates employment and termination procedures by exposing failures in account provisioning and deprovisioning workflows.

Ainformation classification.

Information classification is the process of categorizing data by sensitivity level and has no direct relationship to managing user account lifecycles.

Bcontinuous monitoring.

Continuous monitoring is an ongoing security oversight discipline, not a specific procedure tied to employee status changes.

Cemployment and termination procedures.Correct

Employment and termination procedures govern the full lifecycle of user accounts, from provisioning at hire to deprovisioning at separation. Discovering accounts still assigned to former employees signals a breakdown in the termination workflow, while unverified new accounts indicate gaps in the onboarding and authorization process. Auditing these conditions provides the evidence needed to develop and strengthen those procedures.

Dleast privilege.

Least privilege is a design principle that restricts access rights to the minimum necessary, but it does not define the provisioning and deprovisioning workflow being audited here.

Concept tested: User account lifecycle management and offboarding procedures

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#identity lifecycle#access review#account management#audit

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice