nerdexam
CompTIA

SY0-501 · Question #10

A security administrator is developing controls for creating audit trails and tracking if a PHI data breach is to occur. The administrator has been given the following requirements: All access must…

The correct answer is A. Eliminate shared accounts. C. Implement usage auditing and review. E. Copy logs in real time to a secured WORM drive. First set of requirements: All access must be correlated to a user account. All user accounts must be assigned to a single individual. This means that we must use individual accounts linked to a person, and that we cannot use generic or shared accounts. Second set of…

Submitted by saadiq_pk· Mar 4, 2026Data Loss Prevention

Question

A security administrator is developing controls for creating audit trails and tracking if a PHI data breach is to occur. The administrator has been given the following requirements:

  • All access must be correlated to a user account.
  • All user accounts must be assigned to a single individual.
  • User access to the PHI data must be recorded.
  • Anomalies in PHI data access must be reported.
  • Logs and records cannot be deleted or modified.

Which of the following should the administrator implement to meet the above requirements? (Select THREE).

Options

  • AEliminate shared accounts.
  • BCreate a standard naming convention for accounts.
  • CImplement usage auditing and review.
  • DEnable account lockout thresholds.
  • ECopy logs in real time to a secured WORM drive.
  • FImplement time-of-day restrictions.
  • GPerform regular permission audits and reviews.

How the community answered

(31 responses)
  • A
    81% (25)
  • B
    13% (4)
  • D
    3% (1)
  • F
    3% (1)

Explanation

First set of requirements: * All access must be correlated to a user account. * All user accounts must be assigned to a single individual. This means that we must use individual accounts linked to a person, and that we cannot use generic or shared accounts. Second set of requirements: * User access to the PHI data must be recorded. * Anomalies in PHI data access must be reported. * Logs and records cannot be deleted or modified. For the above to take place ** Auditing of data needs to be logged (success and failures) ** The logs cannot be modified.

Topics

#PHI#audit logging#WORM#access control

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice