Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

A company's security team states that a former employee's login still worked three months after resignation and was used to download client files. Which pairing of the control failure and the principle breached is most accurate?

The failure is not de-provisioning the former employee's access, which breaches the least-privilege and access-control principle. Someone with no continuing business need kept privileges and downloaded confidential files. The other options cite controls such as firewalls, antivirus or backup encryption that the facts never mention.

  1. AFailed de-provisioning of access, breaching the least-privilege and access-control principleCorrect
  2. BWeak encryption of backups, breaching availability
  3. CAbsence of a firewall, breaching non-repudiation
  4. DOutdated antivirus signatures, breaching data integrity

Explanation

The facts show access rights were not revoked on exit, so a person with no business need retained privileges and obtained files, which is an access-control and least-privilege failure. The other options name failures not indicated by the facts. Firewall, antivirus and backup encryption are not mentioned.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions