CISSP Practice Question (Domain 5: Identity and Access Management)
A long-tenured engineer has accumulated access across six business units through internal transfers. A recent audit flagged the account as having excessive privileges, but managers insist the access is "needed for cross-functional projects." What should you do FIRST?
A. Disable unused entitlements based on the last 90 days of activity logs
B. Initiate a formal access recertification with each respective data owner
C. Implement a role-based access control model to replace direct grants
D. Escalate to HR to enforce a job description review
Come back for the answer tomorrow, or study more now!
3
12 comments
Vincent Primiani
7
CISSP Practice Question (Domain 5: Identity and Access Management)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by