There are two components that are asked in this question:
1. User Access Permissions
2. Alignment with data classification
Answer options C and D are general controls that can / should be applied across all classification levels. Hence, these options are wrong.
Leaves you with answer B: By reviewing the access permissions annually, or in case of job changes, the information owner is able to assess on a case by case basis, whether access rights are in accordance to the classification.
C and D can be eliminated because this is an authorization question not an authentication question. A can be eliminated because outsourcing authorization management would only be appropriate in specific contexts. This leaves B as the only possible correct answer.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Josef4CISM
1 month, 2 weeks agoServerBrain
4 months, 1 week agorichck102
1 year, 7 months agocybervds
1 year, 8 months ago