CISSP Practice Question (Domain 5: Identity and Access Management)
An AI-powered identity analytics platform recommends revoking access for 200 employees flagged as "anomalous users" based on behavioral patterns. The system cannot explain why these users were flagged. Business unit managers protest that many are legitimate power users. What should you do FIRST?
A. Implement the revocations with an expedited appeal process for affected employees
B. Require the platform to provide explainable justification before any access changes
C. Suspend automated revocation and conduct manual access reviews for flagged users
D. Adjust the anomaly detection threshold to reduce the number of flagged accounts
Come back for the answer tomorrow, or study more now!
1
19 comments
Vincent Primiani
7
CISSP Practice Question (Domain 5: Identity and Access Management)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by