CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
A company's security team states that a former employee's login still worked three months after resignation and was used to download client files. Which pairing of the control failure and the principle breached is most accurate?
The failure is not de-provisioning the former employee's access, which breaches the least-privilege and access-control principle. Someone with no continuing business need kept privileges and downloaded confidential files. The other options cite controls such as firewalls, antivirus or backup encryption that the facts never mention.
- AFailed de-provisioning of access, breaching the least-privilege and access-control principleCorrect
- BWeak encryption of backups, breaching availability
- CAbsence of a firewall, breaching non-repudiation
- DOutdated antivirus signatures, breaching data integrity
Explanation
The facts show access rights were not revoked on exit, so a person with no business need retained privileges and obtained files, which is an access-control and least-privilege failure. The other options name failures not indicated by the facts. Firewall, antivirus and backup encryption are not mentioned.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- Employees of a Pune logistics firm receive an email that appears to come from the company's CEO, with a link to a page that imitates the cor…
- A Mumbai company's employee finds her files unreadable and a message demanding payment in cryptocurrency for a decryption key. Investigation…
- An attacker enters the string ' OR '1'='1 into the login field of a company's web portal and gains access without a valid password, because …
- Under the CERT-In Directions of 2022, for how long must logs of all ICT systems be maintained securely, within the Indian jurisdiction?
- In the NIST Cybersecurity Framework (version 1.1), which set of five core functions is correctly listed?
- An internal auditor reviews a firm's security programme. The firm has a written information security policy, a vulnerability scanner, and an…