SSCP · Question #146
Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:
The correct answer is A. through access control mechanisms that require identification and authentication and through. Option A is correct because *accountability requires knowing who did something, which is only possible when access control mechanisms enforce identification (declaring an identity) and authentication (proving that identity) - without both, you cannot trace actions back to a speci
Question
Options
- Athrough access control mechanisms that require identification and authentication and through
- Bthrough logical or technical controls involving the restriction of access to systems and the
- Cthrough logical or technical controls but not involving the restriction of access to systems and
- Dthrough access control mechanisms that do not require identification and authentication and
How the community answered
(41 responses)- A90% (37)
- B5% (2)
- C2% (1)
- D2% (1)
Explanation
Option A is correct because accountability requires knowing who did something, which is only possible when access control mechanisms enforce identification (declaring an identity) and authentication (proving that identity) - without both, you cannot trace actions back to a specific individual. Option B is wrong because restricting access to systems alone controls what can be accessed, but doesn't inherently create accountability for who accessed it. Option C compounds that flaw by additionally removing the restriction component, making it doubly insufficient for accountability. Option D is the direct opposite of the correct answer - skipping identification and authentication makes individual accountability impossible, since there's no verified identity to tie to an action.
Memory tip: Think "A = Accountability = Authentication" - the three A's. You can only hold someone accountable if you know who they are (identification) and verified it (authentication); access restriction alone is about authorization, not accountability.
Topics
Community Discussion
No community discussion yet for this question.