Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 406 discussion

Actual exam question from ISC's CISSP
Question #: 406
Topic #: 1
[All CISSP Questions]

An organization is attempting to strengthen the configuration of its enterprise resource planning (ERP) software in order to enforce sufficient segregation of duties (SoD). Which of the following approaches would BEST improve SoD effectiveness?

  • A. Implementation of frequent audits of access and activity in the ERP by a separate team with no operational duties
  • B. Implementation of strengthened authentication measures including mandatory second-factor authentication
  • C. Review of ERP access profiles to enforce the least-privilege principle based on existing employee responsibilities
  • D. Review of employee responsibilities and ERP access profiles to differentiate mission activities from system support activities
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Rollingalx
Highly Voted 1 year, 9 months ago
D is correct. Reviewing ERP access profiles to enforce the least-privilege principle based on existing employee responsibilities is a good practice to ensure that employees have access only to the data and functionality they need to perform their job duties. However, it does not directly address SoD and may not be effective in preventing SoD violations.
upvoted 9 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
Dtony66
Most Recent 5 months, 2 weeks ago
Selected Answer: D
D is correct. C is incorrect because it is really not doing anything to change anything from the current environment, thus by default, it cannot improve it.
upvoted 1 times
...
Hongjun
7 months, 3 weeks ago
Selected Answer: C
the queationwas asking which one wuld best improve SoD. keyword-Improve. how to improve? first, Review ERP profiles basd on empoee responsibilities, also enforce extra menasure : least privilege. this is called improve. A&D - No improve, B- has MFA as extra measure but MFA was for authenticaiton. nothing to dowith SoD.
upvoted 2 times
...
Soleandheel
11 months, 1 week ago
D. Review of employee responsibilities and ERP access profiles to differentiate mission activities from system support activities........seems to make more sense than C.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
D is probably correct BUT D states specifics. I was advised in the CISSP course to go for general overall answers. C seems better since it's not as specific and mentions the right terms. Also, D lists mission and system support, but there are more duties that need to be separated. D also talks about reviewing duties and access in the ERP system, but the question only talks about ERP. It just seems like D is there to throw you off.
upvoted 1 times
...
[Removed]
1 year, 7 months ago
Selected Answer: D
Although CISSP does like audits very much, an audit that covers access and activity (and not job functions) is probably not enough. Also independant team is somewhat vague. We need auditors for an audit, internal or external.
upvoted 1 times
...
Bodatiousbob
1 year, 8 months ago
Selected Answer: D
I agree with D, I was going with C but the word "existing" tells me previous or past tense, meaning that responsibilities could have changed and least privilege rule may cause issues. D shows an active real time analysis of current responsibilities matching job duties
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...