nerdexam
CompTIA

SY0-301 · Question #288

How often, at a MINIMUM, should Sara, an administrator, review the accesses and right of the users on her system?

The correct answer is A. Annually. Security best practices and most compliance frameworks (e.g., PCI-DSS, ISO 27001, NIST) require that user access rights be reviewed at a minimum on an annual basis. This ensures that access privileges remain appropriate over time as roles change, employees leave, or business…

Security program management and oversight

Question

How often, at a MINIMUM, should Sara, an administrator, review the accesses and right of the users on her system?

Options

  • AAnnually
  • BImmediately after an employee is terminated
  • CEvery five years
  • DEvery time they patch the server

How the community answered

(24 responses)
  • A
    88% (21)
  • C
    8% (2)
  • D
    4% (1)

Explanation

Security best practices and most compliance frameworks (e.g., PCI-DSS, ISO 27001, NIST) require that user access rights be reviewed at a minimum on an annual basis. This ensures that access privileges remain appropriate over time as roles change, employees leave, or business needs evolve - a process called access recertification or user access review. Reviewing immediately after termination (B) is a reactive, event-driven task - not a scheduled periodic review. Every five years (C) is far too infrequent and does not meet compliance standards. Reviewing only when patching (D) is unrelated to access management and would be irregular and unpredictable.

Topics

#access review#user rights management#account lifecycle#security policy

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice