exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 922 discussion

Actual exam question from Isaca's CRISC
Question #: 922
Topic #: 1
[All CRISC Questions]

Which of the following is the MOST effective control to ensure user access is maintained on a least-privilege basis?

  • A. Change log review
  • B. User recertification
  • C. Access log monitoring
  • D. User authorization
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cranium
Highly Voted 2 years, 10 months ago
Question states: ensure user access is MAINTAINED on a least-privilege basis? - surely recertification of access is the most appropriate answer here? (B).
upvoted 7 times
...
Staanlee
Most Recent 7 months, 1 week ago
Selected Answer: B
B. User recertification. User recertification is a process in which an organization regularly reviews and verifies the access rights and privileges of its users. This process helps ensure that users have only the access they need to perform their job functions, in line with the principle of least privilege. It involves checking and confirming that the access levels granted to users are still appropriate, and any unnecessary or excessive privileges are revoked. User recertification is a proactive and systematic approach to maintaining least privilege and reducing the risk of unauthorized access.
upvoted 1 times
...
CbtL
1 year ago
Selected Answer: B
Agree with B. The answer at D is the start of the user journey, but recertification is the maintenance.
upvoted 2 times
...
Koulyo
1 year ago
I join the herd with D
upvoted 1 times
Koulyo
1 year ago
meant B
upvoted 2 times
...
...
john_boogieman
1 year, 2 months ago
Selected Answer: B
'B' is Correct.
upvoted 2 times
...
Thuylt12
1 year, 3 months ago
D - User authorization is Correct.
upvoted 1 times
...
Ceecil1959
2 years, 1 month ago
D - User authorization is Correct. As a principle, least privilege falls under the second A in an information security framework known as AAA —authentication, authorization, and accounting (or accountability)
upvoted 1 times
Ceecil1959
1 year, 11 months ago
Yep: I was wrong. Apologies. The correct answer is B.
upvoted 2 times
...
...
Raj1510
2 years, 3 months ago
Agree with B
upvoted 4 times
...
Foree
2 years, 5 months ago
The correct answer is B. User access recertification is the process of continually auditing users' permissions to make sure they have access only to what they need.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago