nerdexam
CompTIA

SY0-301 · Question #397

Various network outages have occurred recently due to unapproved changes to network and security devices. All changes were made using various system credentials. The security analyst has been tasked…

The correct answer is A. User rights and permissions review. Because unauthorized changes were made using 'various system credentials,' the core problem is that too many users have access to privileged accounts. A user rights and permissions review would identify and revoke excessive access, directly reducing the risk of further…

Security program management and oversight

Question

Various network outages have occurred recently due to unapproved changes to network and security devices. All changes were made using various system credentials. The security analyst has been tasked to update the security policy. Which of the following risk mitigation strategies would also need to be implemented to reduce the number of network outages due to unauthorized changes?

Options

  • AUser rights and permissions review
  • BConfiguration management
  • CIncident management
  • DImplement security controls on Layer 3 devices

How the community answered

(21 responses)
  • A
    71% (15)
  • B
    10% (2)
  • C
    14% (3)
  • D
    5% (1)

Why each option

Because unauthorized changes were made using 'various system credentials,' the core problem is that too many users have access to privileged accounts. A user rights and permissions review would identify and revoke excessive access, directly reducing the risk of further unauthorized changes.

AUser rights and permissions reviewCorrect

A user rights and permissions review audits which accounts have access to critical systems and ensures the principle of least privilege is enforced. Since the outages were caused by unauthorized changes made with system credentials, reviewing and restricting who holds those credentials directly addresses the root cause by limiting which users can make changes to network and security devices.

BConfiguration management

Configuration management tracks and controls device configuration states but does not address the underlying problem of too many users having credentials to make unauthorized changes.

CIncident management

Incident management defines how to respond after an event occurs and does not proactively reduce the number of users who can make unauthorized changes.

DImplement security controls on Layer 3 devices

Implementing security controls on Layer 3 devices alone does not address the credential and access problem that allowed unauthorized changes to occur across multiple devices.

Concept tested: User rights and permissions review to enforce least privilege

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#user rights review#change management#access control#risk mitigation

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice