exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 85 discussion

Actual exam question from ISC's CISSP
Question #: 85
Topic #: 1
[All CISSP Questions]

Which one of the following BEST protects vendor accounts that are used for emergency maintenance?

  • A. Vendor access should be disabled until needed
  • B. Frequent monitoring of vendor access
  • C. Role-based access control (RBAC)
  • D. Encryption of routing tables
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rollizo
Highly Voted 2 years, 2 months ago
it is A for sure. If you have this account enable, you don't know how the third party manages the credentials or protects the computer or the keys. Then it is a security hole and it needs to be enable only during outages or big faults.
upvoted 11 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 2 times
...
...
rajkamal0
Highly Voted 1 year, 11 months ago
Selected Answer: C
RBAC is the best answer. "Emergency" access - means active and available 24/7 - A is incorrect IMHO
upvoted 7 times
nuggetbutts
3 weeks, 5 days ago
No, it is the concept of "Just-in-time" Access which is answer A. This is specifically addressed in the exam outline.
upvoted 1 times
...
...
ziyaetuk
Most Recent 2 weeks ago
Selected Answer: A
A. Vendor access should be disabled until needed Explanation: Disabling vendor accounts until they are explicitly needed for emergency maintenance ensures that these accounts cannot be exploited when not in use. This approach minimizes the attack surface and mitigates risks associated with always-on vendor accounts, such as: Unauthorized access due to weak or stolen vendor credentials. Potential misuse by attackers exploiting dormant accounts. By enabling access only on demand, the organization significantly reduces the likelihood of unauthorized access.
upvoted 1 times
...
nuggetbutts
3 weeks, 5 days ago
Selected Answer: C
This is asking about JIT - not RBAC. Answer A is right.
upvoted 1 times
...
Mrawrrr
1 month ago
Selected Answer: A
Disabling vendor access until it is needed is the best way to protect these accounts because it minimizes the window of opportunity for unauthorized access or misuse.
upvoted 2 times
...
deeden
3 months, 4 weeks ago
Selected Answer: C
Role-based access control (RBAC) is the most effective way to protect vendor accounts for emergency maintenance. By assigning specific permissions based on roles, organizations can ensure that vendors have only the necessary access to perform their tasks. This minimizes the risk of unauthorized actions and data breaches.   Here's a breakdown of why the other options are less effective: A. Vendor access should be disabled until needed: While this can reduce risk, it can also hinder emergency response time. B. Frequent monitoring of vendor access: Monitoring is important but doesn't prevent unauthorized access. D. Encryption of routing tables: Unrelated to vendor account protection. By implementing RBAC, organizations can establish granular control over vendor access and reduce the risk of security incidents.
upvoted 1 times
...
8b48948
7 months, 2 weeks ago
Dont think it would be A, would you want to have to re-enable account access in the event of an emergency.
upvoted 1 times
...
CCNPWILL
7 months, 2 weeks ago
A is a better choice than C. Answer is clearly A here. RBAC limits the role of the vendor account. but not enabling it until when its needed is the best way to ensure it gets used properly most of the time.
upvoted 1 times
...
homeysl
8 months, 3 weeks ago
Selected Answer: A
A for attack surface reduction
upvoted 1 times
...
Kyanka
9 months ago
A: Emergency accounts is commonly a type of temporary accounts that needs to be disabled when not in use. Many SRGs/STIGs require these accounts be accounted for and disabled in a timely manner when not actively needed.
upvoted 2 times
...
BabaRed
9 months, 1 week ago
Selected Answer: A
"Emergency" should hopefully mean rarely used. If that's the case, then A. It could be a liability to give a third-party vendor RBAC access when they are rarely needed.
upvoted 1 times
...
stack120566
9 months, 1 week ago
Vendors ( not partners) are usaully called upon in an adhoc basis to offer intermittant serivce These vendors are usually delegated certian RBAC access within an application and possibly within a database in support of the application or service that they are vendor of. The best way is to leave the account disabeld when not in use. Partners may have tools to monitor and authorization to provide on-going support an applications, vendors would not. Vendors are much more restricted.
upvoted 1 times
...
YesPlease
11 months, 4 weeks ago
Selected Answer: A
Answer A) According to CIS (Center for Internet Security) a. Emergency Accounts: Emergency Accounts are intended for short-term use and include restrictions on creation, point of origin, and usage (i.e., time of day, day of week). SEs may establish emergency accounts in response to crisis situations and with the need for rapid account activation. Therefore, emergency account activation may bypass normal account authorization processes. Emergency accounts must be automatically disabled after 24 hours. https://www.cisecurity.org/wp-content/uploads/2020/06/Account-Management-Access-Control-Standard.docx
upvoted 3 times
...
Soleandheel
12 months ago
I'm going with C. RBAC as oppossed to A. Disabling until needed. My reason is becuase of the keyword "Emergency". Enabling a disabled account in time of an emergency can be time consuming and challenging whereas in the case of RBAC, the needed access is all set to go. Logically C. RBAC makes more sense. I believe the correct answer here is C.
upvoted 2 times
...
Moose01
1 year, 1 month ago
A. it is an account that vendor support engineer login and an in house engineer will monitor while he is performing his support work. account is disabled once the job is completed. RBAC for everyone - 99% of the time unless its other type of access control.
upvoted 1 times
...
homeysl
1 year, 1 month ago
Selected Answer: A
A is my answer. It says use for emergency maintenance.
upvoted 1 times
...
aape1
1 year, 2 months ago
Selected Answer: C
C is the Best. This is how you should think to get the answer, not the real-world application. You can only apply one answer, which one will protect it. If you protect the account during disable, what about when you need to enable it for an emergency? Without any RBAC on the vendor account, there is no control when you enable it. The CISSP exam doesn't like no control.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...