nerdexam
GIAC

GCED · Question #22

An outside vulnerability assessment reveals that users have been routinely accessing Gmail from work for over a year, a clear violation of this organization's security policy. The users report "it…

The correct answer is C. Auditing. Audits are used to identify irregular activity in logged (after-the-fact) records. If this activity went unnoticed or uncorrected for over a year, the internal audits failed because they were either incomplete or inaccurate. Authentication, access control and managing user…

Enterprise Network Security and Network Services Security

Question

An outside vulnerability assessment reveals that users have been routinely accessing Gmail from work for over a year, a clear violation of this organization's security policy. The users report "it just started working one day". Later, a network administrator admits he meant to unblock Gmail for just his own IP address, but he made a mistake in the firewall rule. Which security control failed?

Options

  • AAccess control
  • BAuthentication
  • CAuditing
  • DRights management

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    12% (3)
  • C
    76% (19)
  • D
    4% (1)

Explanation

Audits are used to identify irregular activity in logged (after-the-fact) records. If this activity went unnoticed or uncorrected for over a year, the internal audits failed because they were either incomplete or inaccurate. Authentication, access control and managing user rights would not apply as a network admin could be expected to have the ability to configure firewall rules.

Topics

#firewall rules#auditing#access control#security policy

Community Discussion

No community discussion yet for this question.

Full GCED Practice