SY0-501 · Question #252
During a recent audit, it was discovered that several user accounts belonging to former employees were still active and had valid VPN permissions. Which of the following would help reduce the amount o
The correct answer is B. User access reviews. The audit discovered a critical security vulnerability where former employees retained active accounts and VPN access. Implementing regular user access reviews is the direct method to mitigate this risk by ensuring timely deactivation of unnecessary access.
Question
During a recent audit, it was discovered that several user accounts belonging to former employees were still active and had valid VPN permissions. Which of the following would help reduce the amount of risk the organization incurs in this situation in the future?
Options
- ATime-of-day restrictions
- BUser access reviews
- CGroup-based privileges
- DChange management policies
How the community answered
(29 responses)- A7% (2)
- B72% (21)
- C17% (5)
- D3% (1)
Why each option
The audit discovered a critical security vulnerability where former employees retained active accounts and VPN access. Implementing regular user access reviews is the direct method to mitigate this risk by ensuring timely deactivation of unnecessary access.
Time-of-day restrictions limit when an active account can be used but do not address the fundamental issue of why a former employee's account remains active with valid permissions.
User access reviews are a formal, periodic process to re-evaluate who has access to specific resources and why. By conducting these reviews regularly, an organization can identify and remove access for inactive accounts, such as those belonging to former employees, thereby preventing unauthorized access and reducing the risk of security breaches related to stale permissions.
Group-based privileges simplify access management by assigning permissions to groups, but they do not inherently ensure that users who leave the organization are removed from these groups or that their accounts are disabled.
Change management policies govern the process of implementing controlled changes to IT systems and configurations, not the routine auditing and deactivation of user accounts based on employment status changes.
Concept tested: User Access Review for Lifecycle Management
Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview
Topics
Community Discussion
No community discussion yet for this question.