GCIH · Question #371
The incident response team has been working with the various systems teams to find a way to gain root access to systems in event of an incident. It has been proposed that the system teams keep…
The correct answer is B. Create a password reset disk to be used in case of an incident. A password reset disk allows incident responders to generate temporary credentials on demand without exposing standing root passwords stored in envelopes, addressing the VMware team's concern about uncontrolled persistent access.
Question
The incident response team has been working with the various systems teams to find a way to gain root access to systems in event of an incident. It has been proposed that the system teams keep copies of all system passwords and crypto keys in sealed envelopes in a safe in the IT director's office. The envelopes are kept updated by the systems teams and access to the envelopes is logged by the IT director. However, the VMware system team is concerned about unqualified handlers having root access to the VMware host servers. What additional qualifier would make this agreement more agreeable to the VMware system team?
Options
- AAgree that only handlers with VMware experience will access the system
- BCreate a password reset disk to be used in case of an incident
- CHave one member of the incident response team know the password
- DCall VMware system team for incidents involving their systems to gain access
How the community answered
(17 responses)- A6% (1)
- B76% (13)
- C12% (2)
- D6% (1)
Why each option
A password reset disk allows incident responders to generate temporary credentials on demand without exposing standing root passwords stored in envelopes, addressing the VMware team's concern about uncontrolled persistent access.
Restricting access to VMware-experienced handlers is a policy control relying on trust rather than a technical safeguard that enforces the restriction.
A password reset disk provides a controlled, technical mechanism to create new credentials specifically for an incident rather than storing the actual root password in an envelope accessible to any handler. After the incident, the password is reset again, ensuring the VMware team's permanent credentials are never directly exposed. This gives the VMware team confidence that access is temporary and does not leave standing credentials with potentially unqualified responders.
Having one IR team member know the standing root password still exposes permanent credentials to someone the VMware team may consider unqualified for their environment.
Requiring the VMware team to be called creates an availability dependency that can delay incident response and is not a reliable or scalable technical solution.
Concept tested: Incident response credential management and least-privilege access
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.