SY0-501 · Question #83
A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On…
The correct answer is B. Routine auditing. The incident involving a demoted supervisor modifying a confidential database highlights the importance of implementing timely detective controls to identify unauthorized actions quickly.
Question
A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On Monday morning, the database administrator reported that log files indicated that several records were missing from the database. Which of the following risk mitigation strategies should have been implemented when the supervisor was demoted?
Options
- AIncident management
- BRoutine auditing
- CIT governance
- DMonthly user rights reviews
How the community answered
(22 responses)- A14% (3)
- B77% (17)
- C5% (1)
- D5% (1)
Why each option
The incident involving a demoted supervisor modifying a confidential database highlights the importance of implementing timely detective controls to identify unauthorized actions quickly.
Incident management is a reactive process for responding to and recovering from security breaches or operational failures *after* they have occurred, not a proactive measure to prevent or detect them at the time of demotion.
Routine auditing involves the regular collection and review of system logs and user activity, which would promptly detect unauthorized modifications by a demoted supervisor. If this process was actively performed and timely, it would have identified the database tampering quickly, enabling a faster response and limiting potential data loss.
IT governance refers to the overall framework for ensuring IT aligns with business objectives and managing IT risks at a strategic level, rather than being a specific operational strategy for immediate user action mitigation.
Monthly user rights reviews are too infrequent for critical events like a supervisor's demotion, which requires immediate revocation or much more frequent verification of access rights to prevent data tampering.
Concept tested: Detective controls, security auditing, timely log review
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/auditing-best-practices
Topics
Community Discussion
No community discussion yet for this question.