CISSP · Question #557
Which of the following is a process in the access provisioning lifecycle that will MOST likely identify access aggregation issues?
The correct answer is C. Review. In the access provisioning lifecycle, periodic access reviews are the primary mechanism for detecting access aggregation (privilege creep), where users accumulate excessive permissions over time.
Question
Options
- ATest
- BAssessment
- CReview
- DPeer review
How the community answered
(33 responses)- A3% (1)
- B6% (2)
- C88% (29)
- D3% (1)
Why each option
In the access provisioning lifecycle, periodic access reviews are the primary mechanism for detecting access aggregation (privilege creep), where users accumulate excessive permissions over time.
Testing in the access provisioning lifecycle typically validates that provisioning workflows and controls function correctly, not that accumulated user entitlements are appropriate.
An assessment is generally a broader, one-time or periodic evaluation of security posture or risk, not a continuous lifecycle process focused on individual user entitlement aggregation.
Access Reviews are a structured, recurring process in the identity and access management lifecycle specifically designed to evaluate whether current user permissions remain appropriate. This process directly surfaces access aggregation issues - where a user has accumulated excessive or conflicting entitlements across roles or systems over time - by systematically comparing current access against business need and least-privilege principles.
Peer review in provisioning contexts typically involves a colleague validating a specific access request at the time it is made, which does not address the cumulative buildup of access rights over time.
Concept tested: Access review detecting privilege creep in IAM lifecycle
Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview
Topics
Community Discussion
No community discussion yet for this question.