exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 50 discussion

Actual exam question from ISC's CISSP
Question #: 50
Topic #: 1
[All CISSP Questions]

In a quarterly system access review, an active privileged account was discovered that did not exist in the prior review on the production system. The account was created one hour after the previous access review. Which of the following is the BEST option to reduce overall risk in addition to quarterly access reviews?

  • A. Implement bi-annual reviews.
  • B. Create policies for system access.
  • C. Implement and review risk-based alerts.
  • D. Increase logging levels.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
N00b1e
Highly Voted 2 years, 5 months ago
Selected Answer: B
I agree with B. If you create a policy on when system accounts can be created, they would have to be logged or someone would have to actively break policy. Think like a manager!
upvoted 22 times
1460168
6 months, 4 weeks ago
Think like a Manager. Do not touch anything, tell others how to do it.
upvoted 1 times
...
Jamati
2 years, 3 months ago
I agree, the key here is to think like a manager.
upvoted 2 times
...
jackdryan
1 year, 10 months ago
B is correct
upvoted 1 times
...
...
thomass
Highly Voted 2 years, 5 months ago
sorry, should be C?
upvoted 10 times
Ramye
9 months, 1 week ago
Why though? Without the established policy, there won’t be any concern of creating accts, hence there should not be any trigger or anything like that. So answer most likely B. But if anyone has confirmed answer I’ll be happy to take that. Thx
upvoted 2 times
...
...
iRyae
Most Recent 1 week ago
Selected Answer: C
While B (Create policies for system access) is important and should already be in place, it doesn't directly address the specific issue of a rogue privileged account being created between reviews. Policies are guidelines, but they don't actively prevent or detect this type of activity in real-time. Risk-based alerts, on the other hand, do address this gap. By implementing alerts for specific high-risk actions (like the creation of new privileged accounts, especially outside of normal change windows), the security team can be notified immediately when such an event occurs. This allows for rapid investigation and mitigation, significantly reducing the window of opportunity for malicious activity. It complements the quarterly reviews by providing continuous monitoring and detection capabilities.
upvoted 1 times
...
Isebarry
3 weeks, 4 days ago
Selected Answer: B
Creating policies for system access is more important than increasing logging levels in this case. The policies created should actually include logging. That way, policy drives system access and logging levels.
upvoted 1 times
...
Fouad777
2 months, 2 weeks ago
Selected Answer: C
C. Implement and review risk-based alerts. Here's why: Risk-based alerts provide real-time or near-real-time monitoring and alerting for unusual or suspicious activities, such as the creation of new privileged accounts. This enables a more proactive approach to security, allowing the organization to quickly identify and respond to potential threats. Implementing bi-annual reviews (A) would reduce the frequency of reviews, potentially increasing the risk of unnoticed issues. Creating policies for system access (B) is important, but on its own, it may not provide the necessary real-time detection and response capabilities. Increasing logging levels (D) can be helpful, but without active monitoring and alerting, it might not effectively reduce risk. Risk-based alerts enhance your security posture by providing timely information and enabling swift action to mitigate potential risks.
upvoted 1 times
...
Bietchasup
2 months, 4 weeks ago
Selected Answer: B
nobody ever comes back on here after failing or passing lol
upvoted 4 times
...
KennethLZK
3 months ago
Selected Answer: B
From a managerial standpoint, establishing clear policies is fundamental. Policies provide a framework for consistent and secure access management, ensuring that all actions are governed by well-defined rules. This helps in maintaining control and accountability, which are key managerial responsibilities.
upvoted 1 times
...
GabrielVillamizar
6 months, 3 weeks ago
Selected Answer: C
En base a la pregunta, al C es la correcta
upvoted 1 times
...
Nithstar
7 months ago
answer c is correct sinc alerts can detect changes
upvoted 2 times
...
CCNPWILL
8 months, 3 weeks ago
Selected Answer: C
B is a good answer, but C is better.
upvoted 1 times
...
Jenkins3mol
9 months, 4 weeks ago
Selected Answer: C
Well, this is quite contentious a question, huh. But as you can see, you will have to change the policy along the way, anyway, every time after you have done a quarterly check. So B would be out of the question very necessary, fundamental and routine; however, C is directly resolving the problem depicted in the question body, so C is more relevant an answer which is heavily implied by the question composer. And C is the conclusion that you should have as a manager after adopting doubleloop thinking method.
upvoted 4 times
...
jieaws
10 months, 2 weeks ago
B policies encompasses C alert implementation. B enforces C and holds the stake holders (usually Sr professionals) accountable for implementation alignment with the police B. I finally understand why CISSP exam emphasizes managerial view. B takes precedence C. In order words, B must be in place first. I choose B.
upvoted 1 times
...
AshStevens
10 months, 3 weeks ago
Selected Answer: C
C. The trick here is that it was created immediately after the previous check. The implication is that the user is very aware that it wouldn't be allowed UNDER THE POLICIES THEY ALREADY HAVE, and are choosing to ignore that. A new policy does not enforce compliance, but setting up alerts to monitor would immediately detect non-compliance regardless of the users intent or timing.
upvoted 2 times
...
Vaneck
11 months, 1 week ago
Selected Answer: C
The best option for reducing overall risk in addition to quarterly access reviews is : C. Implement and review risk-based alerts. Implementing and reviewing risk-based alerts would enable early detection of suspicious or unauthorized activity, such as the creation of new privileged accounts, and react accordingly. This proactive approach helps to identify and mitigate potential risks in real time, rather than relying solely on periodic reviews.
upvoted 1 times
...
john_boogieman
11 months, 1 week ago
Selected Answer: C
In the context of the scenario provided, implementing and reviewing risk-based alerts be the better option for immediate risk mitigation.
upvoted 1 times
...
homeysl
11 months, 2 weeks ago
Selected Answer: B
Policy vs. Alert
upvoted 1 times
...
lexvather
1 year ago
C. the key is here was created 1 hour after of previous review, so they will detect the account until the next review will be performed. The best option is C. Answer B should be a good option but not accomplish the detection and response.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago