SY0-301 · Question #288
How often, at a MINIMUM, should Sara, an administrator, review the accesses and right of the users on her system?
The correct answer is A. Annually. Security best practices and most compliance frameworks (e.g., PCI-DSS, ISO 27001, NIST) require that user access rights be reviewed at a minimum on an annual basis. This ensures that access privileges remain appropriate over time as roles change, employees leave, or business…
Question
How often, at a MINIMUM, should Sara, an administrator, review the accesses and right of the users on her system?
Options
- AAnnually
- BImmediately after an employee is terminated
- CEvery five years
- DEvery time they patch the server
How the community answered
(24 responses)- A88% (21)
- C8% (2)
- D4% (1)
Explanation
Security best practices and most compliance frameworks (e.g., PCI-DSS, ISO 27001, NIST) require that user access rights be reviewed at a minimum on an annual basis. This ensures that access privileges remain appropriate over time as roles change, employees leave, or business needs evolve - a process called access recertification or user access review. Reviewing immediately after termination (B) is a reactive, event-driven task - not a scheduled periodic review. Every five years (C) is far too infrequent and does not meet compliance standards. Reviewing only when patching (D) is unrelated to access management and would be irregular and unpredictable.
Topics
Community Discussion
No community discussion yet for this question.