CISSP · Question #1249
An internal audit for an organization recently identified malicious actions by a user account. Upon further investigation, it was determined the offending user account was used by multiple people at m
The correct answer is C. Ensure each user has their own unique account,. The best method to prevent the problem of malicious actions by a user account that was used by multiple people at multiple locations simultaneously for various services and applications in the future is to ensure each user has their own unique account. A user account is a record
Question
Options
- AEnsure the security information and event management (SIEM) is set to alert.
- BInform users only one user should be using the account at a time.
- CEnsure each user has their own unique account,
- DAllow several users to share a generic account.
How the community answered
(38 responses)- A11% (4)
- B5% (2)
- C84% (32)
Explanation
The best method to prevent the problem of malicious actions by a user account that was used by multiple people at multiple locations simultaneously for various services and applications in the future is to ensure each user has their own unique account. A user account is a record or a profile that identifies and authenticates a user and grants them access rights and privileges to the organization's resources and systems. A user account should be unique and personal, meaning that it should belong to and be used by only one individual user, and that it should reflect the user's identity and role within the organization. Ensuring each user has their own unique account can prevent the problem of malicious actions by a user account that was used by multiple people at multiple locations simultaneously for various services and applications in the future, because it Improve the accountability and the traceability of the user actions, as each user can be linked and attributed to their own account and activities, and any malicious or unauthorized actions can be detected and investigated more easily and accurately. Enhance the security and the privacy of the user data and information, as each user can have their own password and encryption keys, and any sensitive or confidential data or information can be protected and isolated from other users or parties. Enforce the principle of least privilege and the segregation of duties, as each user can have their own access rights and privileges, and any excessive or conflicting access rights or privileges can be avoided or restricted.
Topics
Community Discussion
No community discussion yet for this question.