SY0-301 · Question #397
Various network outages have occurred recently due to unapproved changes to network and security devices. All changes were made using various system credentials. The security analyst has been tasked…
The correct answer is A. User rights and permissions review. Because unauthorized changes were made using 'various system credentials,' the core problem is that too many users have access to privileged accounts. A user rights and permissions review would identify and revoke excessive access, directly reducing the risk of further…
Question
Various network outages have occurred recently due to unapproved changes to network and security devices. All changes were made using various system credentials. The security analyst has been tasked to update the security policy. Which of the following risk mitigation strategies would also need to be implemented to reduce the number of network outages due to unauthorized changes?
Options
- AUser rights and permissions review
- BConfiguration management
- CIncident management
- DImplement security controls on Layer 3 devices
How the community answered
(21 responses)- A71% (15)
- B10% (2)
- C14% (3)
- D5% (1)
Why each option
Because unauthorized changes were made using 'various system credentials,' the core problem is that too many users have access to privileged accounts. A user rights and permissions review would identify and revoke excessive access, directly reducing the risk of further unauthorized changes.
A user rights and permissions review audits which accounts have access to critical systems and ensures the principle of least privilege is enforced. Since the outages were caused by unauthorized changes made with system credentials, reviewing and restricting who holds those credentials directly addresses the root cause by limiting which users can make changes to network and security devices.
Configuration management tracks and controls device configuration states but does not address the underlying problem of too many users having credentials to make unauthorized changes.
Incident management defines how to respond after an event occurs and does not proactively reduce the number of users who can make unauthorized changes.
Implementing security controls on Layer 3 devices alone does not address the credential and access problem that allowed unauthorized changes to occur across multiple devices.
Concept tested: User rights and permissions review to enforce least privilege
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.