nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #102

Which of these is NOT a best practice in access management? ()

The correct answer is A. Trust but verify. 'Trust but verify' is an outdated security mindset and is explicitly rejected by modern Zero Trust security frameworks, which operate on the principle of 'never trust, always verify.' In access management best practices, no user, device, or system should be implicitly trusted…

Access Controls Concepts

Question

Which of these is NOT a best practice in access management? ()

Options

  • ATrust but verify
  • BPeriodically assessing whether user permissions still apply
  • CGiving only the right amount of permission
  • DRequesting a justification when upgrading permission

How the community answered

(28 responses)
  • A
    89% (25)
  • B
    7% (2)
  • D
    4% (1)

Explanation

'Trust but verify' is an outdated security mindset and is explicitly rejected by modern Zero Trust security frameworks, which operate on the principle of 'never trust, always verify.' In access management best practices, no user, device, or system should be implicitly trusted - trust must be continuously earned and validated. The other options are all legitimate access management best practices: periodic access reviews (B) support the principle of least privilege over time, granting only necessary permissions (C) is least privilege, and requiring justification for privilege escalation (D) supports accountability and auditability.

Topics

#Access Management#Best Practices#Access Control Principles#Least Privilege

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice