nerdexam
CompTIA

SY0-301 · Question #691

A supervisor in the human resources department has been given additional job duties in the accounting department. Part of their new duties will be to check the daily balance sheet calculations on…

The correct answer is C. The supervisor should be added to the accounting group while maintaining their membership in the. This question tests the principle of least privilege combined with practical access management. The supervisor still performs human resources duties, so removing them from the HR group (Option B) would break their existing access needs. The correct approach is to add the…

Security operations

Question

A supervisor in the human resources department has been given additional job duties in the accounting department. Part of their new duties will be to check the daily balance sheet calculations on spreadsheets that are restricted to the accounting group. In which of the following ways should the account be handled?

Options

  • AThe supervisor should be allowed to have access to the spreadsheet files, and their membership
  • BThe supervisor should be removed from the human resources group and added to the accounting group.
  • CThe supervisor should be added to the accounting group while maintaining their membership in the
  • DThe supervisor should only maintain membership in the human resources group.

How the community answered

(47 responses)
  • A
    13% (6)
  • B
    9% (4)
  • C
    74% (35)
  • D
    4% (2)

Explanation

This question tests the principle of least privilege combined with practical access management. The supervisor still performs human resources duties, so removing them from the HR group (Option B) would break their existing access needs. The correct approach is to add the supervisor to the accounting group while retaining HR membership (Option C). This grants only the additional access required for the new duties without disrupting current responsibilities. Simply maintaining only HR membership (Option D) would prevent them from doing their new accounting work. The key principle here is: grant the minimum necessary access for all roles a user actively holds, without removing legitimate existing access.

Topics

#group membership#least privilege#IAM#access control

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice