SY0-501 · Question #227
An audit takes place after company-wide restricting, in which several employees changed roles. The following deficiencies are found during the audit regarding access to confidential data: Which of the
The correct answer is A. Implement separation of duties for the payroll department.. To prevent future audit findings regarding inappropriate access to confidential data following role changes, implementing separation of duties is the most effective preventative measure.
Question
An audit takes place after company-wide restricting, in which several employees changed roles. The following deficiencies are found during the audit regarding access to confidential data:
Which of the following would be the BEST method to prevent similar audit findings in the future?
Exhibit
Options
- AImplement separation of duties for the payroll department.
- BImplement a DLP solution on the payroll and human resources servers.
- CImplement rule-based access controls on the human resources server.
- DImplement regular permission auditing and reviews.
How the community answered
(38 responses)- A71% (27)
- B5% (2)
- C16% (6)
- D8% (3)
Why each option
To prevent future audit findings regarding inappropriate access to confidential data following role changes, implementing separation of duties is the most effective preventative measure.
Implementing separation of duties (SoD) ensures that no single individual has complete control over a critical or sensitive process, such as accessing and managing confidential payroll data. By dividing responsibilities and requiring multiple individuals for sensitive actions, SoD directly mitigates the risk of unauthorized access or misuse by employees, especially after role changes, thereby preventing future audit findings related to excessive permissions.
A DLP solution primarily prevents sensitive data from leaving the organization's control, rather than directly preventing inappropriate internal access due to flawed access controls after role changes.
While rule-based access controls are a good general approach to managing access, simply implementing them does not inherently prevent deficiencies if the underlying rules are not structured according to principles like separation of duties to limit excessive privileges.
Regular permission auditing and reviews are crucial for identifying existing deficiencies but do not inherently prevent them from occurring in the first place, which is the goal specified in the question.
Concept tested: Security principles: Separation of Duties (SoD)
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/identity-access-control-best-practices#segregation-of-duties
Topics
Community Discussion
No community discussion yet for this question.
