nerdexam
(ISC)2

CISSP · Question #740

When designing a networked Information System (IS) where there will be several different types of individual access, what is the FIRST step that should be taken to ensure all access control requiremen

The correct answer is B. Create a user access matrix.. The first step to take when designing a networked Information System (IS) where there will be several different types of individual access is to create a user access matrix. A user access matrix is a table that defines the access rights and permissions of each user or user group

Submitted by naveen.iyer· Mar 5, 2026Identity and Access Management

Question

When designing a networked Information System (IS) where there will be several different types of individual access, what is the FIRST step that should be taken to ensure all access control requirements are addressed?

Options

  • ACreate a user profile.
  • BCreate a user access matrix.
  • CDevelop an Access Control List (ACL).
  • DDevelop a Role Based Access Control (RBAC) list.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    75% (21)
  • C
    4% (1)
  • D
    14% (4)

Explanation

The first step to take when designing a networked Information System (IS) where there will be several different types of individual access is to create a user access matrix. A user access matrix is a table that defines the access rights and permissions of each user or user group to each resource or function in the system. A user access matrix helps to ensure that all access control requirements are addressed, such as the principle of least privilege, the principle of separation of duties, and the principle of need to know. A user access matrix also helps to simplify and standardize the implementation and administration of access control policies and mechanisms.

Topics

#access control design#user access matrix#authorization matrix#access control requirements

Community Discussion

No community discussion yet for this question.

Full CISSP Practice