nerdexam
CompTIA

SY0-301 · Question #221

An internal auditor is concerned with privilege creep that is associated with transfers inside the company. Which mitigation measure would detect and correct this?

The correct answer is A. User rights reviews. Privilege creep occurs when users accumulate access rights beyond their current role, often due to internal transfers. User rights reviews detect and correct this by periodically auditing what access each user actually holds.

Security operations

Question

An internal auditor is concerned with privilege creep that is associated with transfers inside the company. Which mitigation measure would detect and correct this?

Options

  • AUser rights reviews
  • BLeast privilege and job rotation
  • CChange management
  • DChange Control

How the community answered

(21 responses)
  • A
    90% (19)
  • B
    5% (1)
  • D
    5% (1)

Why each option

Privilege creep occurs when users accumulate access rights beyond their current role, often due to internal transfers. User rights reviews detect and correct this by periodically auditing what access each user actually holds.

AUser rights reviewsCorrect

User rights reviews are a detective and corrective control that periodically audit all user accounts and permissions, identifying access that was granted for previous roles but never revoked. This directly addresses privilege creep by comparing current permissions against current job requirements. Reviews can then trigger removal of excess privileges, bringing users back into compliance with least privilege principles.

BLeast privilege and job rotation

Least privilege and job rotation are preventive controls that reduce the chance of privilege creep occurring, but they do not detect or correct accumulated excess permissions after the fact.

CChange management

Change management governs how changes are requested and approved in an environment but does not specifically audit or remediate existing user permission assignments.

DChange Control

Change control is a subset of change management focused on controlling modifications to systems, not on reviewing or correcting user access rights.

Concept tested: Detecting and correcting privilege creep via access reviews

Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Topics

#privilege creep#user rights review#access management#account audit

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice