SSCP · Question #378
SSCP Question #378: Real Exam Question with Answer & Explanation
The correct answer is A: through access control mechanisms that require identification and authentication and. Accountability requires that actions can be traced to a specific individual. This is achieved by: (1) Identification - claiming an identity; (2) Authentication - proving that identity; and (3) Audit trails - recording what that authenticated identity did. All three components tog
Question
Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:
Options
- Athrough access control mechanisms that require identification and authentication and
- Bthrough logical or technical controls involving the restriction of access to systems and the
- Cthrough logical or technical controls but not involving the restriction of access to systems
- Dthrough access control mechanisms that do not require identification and authentication
Explanation
Accountability requires that actions can be traced to a specific individual. This is achieved by: (1) Identification - claiming an identity; (2) Authentication - proving that identity; and (3) Audit trails - recording what that authenticated identity did. All three components together create accountability. Without identification and authentication, audit logs cannot be tied to a specific person. Option B describes access restriction but omits the audit trail component. Options C and D are incorrect because they remove required elements (audit trails, or I&A) that are essential to accountability.
Topics
Community Discussion
No community discussion yet for this question.