SY0-501 · Question #235
A Chief Executive Officer (CEO) suspects someone in the lab testing environment is stealing confidential information after working hours when no one else is around. Which of the following actions…
The correct answer is D. Require swipe-card access to enter the lab. To prevent a lab employee from stealing confidential information after hours, implementing a physical access control like swipe-card entry directly addresses the unauthorized physical presence threat.
Question
A Chief Executive Officer (CEO) suspects someone in the lab testing environment is stealing confidential information after working hours when no one else is around. Which of the following actions can help to prevent this specific threat?
Options
- AImplement time-of-day restrictions.
- BAudit file access times.
- CSecretly install a hidden surveillance camera.
- DRequire swipe-card access to enter the lab.
How the community answered
(69 responses)- A7% (5)
- B13% (9)
- C3% (2)
- D77% (53)
Why each option
To prevent a lab employee from stealing confidential information after hours, implementing a physical access control like swipe-card entry directly addresses the unauthorized physical presence threat.
Implementing time-of-day restrictions typically applies to logical system access, not physical entry, and would not prevent an already physically present individual from accessing systems or data after hours if they are physically in the lab.
Auditing file access times is a detective control that identifies when files were accessed, but it does not prevent the initial unauthorized access or theft of information.
Secretly installing a hidden surveillance camera is a detective control that can record events but does not physically prevent the act of stealing information, and may have legal and privacy implications.
Requiring swipe-card access to enter the lab is a physical security control that restricts entry to authorized personnel during specific times or periods. This directly prevents an unauthorized person, even an employee, from physically entering the lab after working hours when no one else is around to steal information.
Concept tested: Physical access control for sensitive environments
Source: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credentials-access-threats
Topics
Community Discussion
No community discussion yet for this question.