ISC2 CISSP Provisioning Deprovisioning Service Accounts And Privilege Lifecycle Practice Test
5 Identity and Access Management (IAM) • 26 original questions
This CISSP practice test focuses on provisioning deprovisioning service accounts and privilege lifecycle through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Contoso Financial is revising controls for its payment processing service. A review highlights Account access review for users, systems, and services. The business continuity lead must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The identity population includes 5,800 workforce, service, or device identities.
Correct answer: B
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
An auditor asks Lucerne Publishing to demonstrate how it handles Provisioning and deprovisioning in the software delivery pipeline. The privacy and compliance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The identity population includes 7,500 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
After a business change, Lamna Healthcare discovers that Service-account management is not handled consistently for the AI-assisted customer service platform. The security architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The identity population includes 9,200 workforce, service, or device identities.
Correct answer: B
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Fourth Coffee is preparing a security decision for the global collaboration platform. The decision involves Role definition and transition. The security operations manager must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The identity population includes 1,800 workforce, service, or device identities.
Correct answer: B
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
During a risk workshop for the e-commerce application, the team identifies Privilege escalation and sudo auditing as the deciding issue. The business continuity lead is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The identity population includes 3,500 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
A control owner at Proseware Labs proposes a quick technical fix for Account access review for users, systems, and services in the clinical records environment. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The identity population includes 5,200 workforce, service, or device identities.
Correct answer: C
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Southridge Media is standardizing security across several business units. The remote access service raises a question about Account access review for users, systems, and services. The security architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The identity population includes 6,900 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while accounting for third-party and lifecycle dependencies.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while accounting for third-party and lifecycle dependencies.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
During a business continuity exercise, Adventure Works asks the security operations manager to address Provisioning and deprovisioning for its customer identity platform. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The identity population includes 8,600 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while maintaining the organization’s stated risk appetite.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while maintaining the organization’s stated risk appetite.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
VanArsdel Energy is revising controls for its data analytics lake. A review highlights Service-account management. The business continuity lead must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The identity population includes 1,200 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while meeting the business objective with the least unnecessary operational complexity.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
An auditor asks Northwind Health to demonstrate how it handles Role definition and transition in the branch-office network. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The identity population includes 2,900 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while keeping the control sustainable for normal operations.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while keeping the control sustainable for normal operations.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
After a business change, Coho Insurance discovers that Privilege escalation and sudo auditing is not handled consistently for the industrial control network. The security architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The identity population includes 4,600 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring the decision can be repeated consistently across business units.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring the decision can be repeated consistently across business units.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Correct answer: B
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while preserving clear accountability and audit evidence.
Option review:
A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while preserving clear accountability and audit evidence.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
During a risk workshop for the payment processing service, the team identifies Provisioning and deprovisioning as the deciding issue. The business continuity lead is expected to address the control objective while protecting sensitive data throughout the change. What is the MOST appropriate course of action? The identity population includes 8,000 workforce, service, or device identities.
Correct answer: B
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while protecting sensitive data throughout the change.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while protecting sensitive data throughout the change.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
A control owner at City Power proposes a quick technical fix for Service-account management in the software delivery pipeline. The privacy and compliance lead must address the control objective while preserving availability of the critical business service. What should happen FIRST? The identity population includes 600 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while preserving availability of the critical business service.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Tailspin Logistics is standardizing security across several business units. The AI-assisted customer service platform raises a question about Role definition and transition. The security architect needs to address the control objective without replacing governance with a technology-only shortcut. Which action provides the BEST governance and security outcome? The identity population includes 2,300 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without replacing governance with a technology-only shortcut.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without replacing governance with a technology-only shortcut.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
During a post-incident improvement program, Alpine Sports asks the security operations manager to address Privilege escalation and sudo auditing for its global collaboration platform. The requirement is to address the control objective while keeping the process defensible to auditors and business owners. What should the organization do FIRST? The identity population includes 4,000 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the process defensible to auditors and business owners.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the process defensible to auditors and business owners.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Fabrikam Manufacturing is revising controls for its e-commerce application. A review highlights Account access review for users, systems, and services. The business continuity lead must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The identity population includes 5,700 workforce, service, or device identities.
Correct answer: C
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
An auditor asks Trey Research to demonstrate how it handles Provisioning and deprovisioning in the clinical records environment. The privacy and compliance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The identity population includes 7,400 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
After a business change, Margie Travel discovers that Service-account management is not handled consistently for the remote access service. The security architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The identity population includes 9,100 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Wide World Importers is preparing a security decision for the customer identity platform. The decision involves Role definition and transition. The security operations manager must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The identity population includes 1,700 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
During a risk workshop for the data analytics lake, the team identifies Privilege escalation and sudo auditing as the deciding issue. The business continuity lead is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The identity population includes 3,400 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
A control owner at Litware Services proposes a quick technical fix for Account access review for users, systems, and services in the branch-office network. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The identity population includes 5,100 workforce, service, or device identities.
Correct answer: C
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Humongous Insurance is standardizing security across several business units. The industrial control network raises a question about Provisioning and deprovisioning. The security architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The identity population includes 6,800 workforce, service, or device identities.
Correct answer: B
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while accounting for third-party and lifecycle dependencies.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while accounting for third-party and lifecycle dependencies.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
During a quarterly security review, Woodgrove Bank asks the security operations manager to address Service-account management for its research data repository. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The identity population includes 8,500 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while maintaining the organization’s stated risk appetite.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while maintaining the organization’s stated risk appetite.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Relecloud Systems is revising controls for its payment processing service. A review highlights Role definition and transition. The business continuity lead must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The identity population includes 1,100 workforce, service, or device identities.
Correct answer: A
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while meeting the business objective with the least unnecessary operational complexity.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
An auditor asks Contoso Financial to demonstrate how it handles Privilege escalation and sudo auditing in the software delivery pipeline. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The identity population includes 2,800 workforce, service, or device identities.
Correct answer: D
Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the control sustainable for normal operations.
Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.
Popular posts
Recent Posts
