nerdexam
CompTIA

SY0-501 · Question #83

A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On…

The correct answer is B. Routine auditing. The incident involving a demoted supervisor modifying a confidential database highlights the importance of implementing timely detective controls to identify unauthorized actions quickly.

Submitted by daniela_cl· Mar 4, 2026Security program management and oversight

Question

A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On Monday morning, the database administrator reported that log files indicated that several records were missing from the database. Which of the following risk mitigation strategies should have been implemented when the supervisor was demoted?

Options

  • AIncident management
  • BRoutine auditing
  • CIT governance
  • DMonthly user rights reviews

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    77% (17)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The incident involving a demoted supervisor modifying a confidential database highlights the importance of implementing timely detective controls to identify unauthorized actions quickly.

AIncident management

Incident management is a reactive process for responding to and recovering from security breaches or operational failures *after* they have occurred, not a proactive measure to prevent or detect them at the time of demotion.

BRoutine auditingCorrect

Routine auditing involves the regular collection and review of system logs and user activity, which would promptly detect unauthorized modifications by a demoted supervisor. If this process was actively performed and timely, it would have identified the database tampering quickly, enabling a faster response and limiting potential data loss.

CIT governance

IT governance refers to the overall framework for ensuring IT aligns with business objectives and managing IT risks at a strategic level, rather than being a specific operational strategy for immediate user action mitigation.

DMonthly user rights reviews

Monthly user rights reviews are too infrequent for critical events like a supervisor's demotion, which requires immediate revocation or much more frequent verification of access rights to prevent data tampering.

Concept tested: Detective controls, security auditing, timely log review

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/auditing-best-practices

Topics

#privilege management#access revocation#insider threat#audit logging

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice