Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 142 discussion

Actual exam question from ISC's CISSP
Question #: 142
Topic #: 1
[All CISSP Questions]

A company developed a web application which is sold as a Software as a Service (SaaS) solution to the customer. The application is hosted by a web server running on a specific operating system (OS) on a virtual machine (VM). During the transition phase of the service, it is determined that the support team will need access to the application logs. Which of the following privileges would be the MOST suitable?

  • A. Administrative privileges on the hypervisor
  • B. Administrative privileges on the application folders
  • C. Administrative privileges on the web server
  • D. Administrative privileges on the OS
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
deeden
3 months, 2 weeks ago
Selected Answer: B
Agree with B. Admin access to web server allow access to all other application being hosted on that web server. Although there's only one SaaS mentioned, but correct... least privilege principle. Here's a simplified hierarchical breakdown from the hypervisor to the application folder: >Hypervisor: Manages virtual machines. >Operating System: Provides the base environment for applications. >Web Server: Software application responsible for serving web content. > Web Server Configuration Files: Store settings for the web server. > Log Files: Record server activity. > Application Folders: Contain specific web applications. > Application Code: Source code for the application. > Application Data: Configuration files, databases, and other data. > Application Logs: Specific logs for the application.
upvoted 3 times
...
TheManiac
6 months, 1 week ago
Selected Answer: B
Least priv is the key here. Dont give access more than they need. application folders access is what they need. So, C. Administrative privileges on the web server is wrong. you break least priv here
upvoted 4 times
...
stack120566
8 months, 3 weeks ago
Option B is correct . I agree with 629f731.Those of us that have had to scour logs understand that the application does not hold all of the logs. In many cases applications log very little.
upvoted 1 times
...
629f731
10 months, 2 weeks ago
Selected Answer: C
Option B involves granting administrative privileges directly to the application folders. While it can provide access to application logs, it also carries additional risks. With access to application folders, changes or modifications can be made to other system files, which could compromise the stability or security of the application if inadvertent or unauthorized modifications are made. Additionally, logs may not be exclusively contained in specific application folders, so limiting privileges to folders only does not guarantee complete access to all necessary logs. For these reasons, option C (administrative privileges on the web server) might be more appropriate as it allows more controlled access to logs without providing direct access to other system components.
upvoted 4 times
...
Soleandheel
11 months, 3 weeks ago
B. Administrative privileges on the application folders
upvoted 2 times
...
Soleandheel
11 months, 3 weeks ago
least privilege guys. You want to give them access to only what they need to do the Job. No more, no less.
upvoted 2 times
...
Ukpes
1 year ago
B is the right answer. You do not need to have admin privileges to the web server but rather to the app folders. Reason: the principle of least privilege!
upvoted 1 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: C
The MOST suitable privilege in this scenario would be C. Administrative privileges on the web server. This would allow the support team to access and analyze the application logs without compromising the security of the hypervisor or the underlying OS. Administrative privileges on the application folders or the OS may be too broad and could potentially allow access to sensitive information beyond just the logs.
upvoted 2 times
...
Bach1968
1 year, 4 months ago
Selected Answer: B
B. Administrative privileges on the application folders
upvoted 1 times
...
HughJassole
1 year, 5 months ago
So we have no idea where the application logs are written to. I am a linux admin and some apps write in their own folders, some write to /var/log, the same place the OS writes to. So I don't think this question provides enough info to answer. A best guess would be B, least privilege, but there is no way to know.
upvoted 2 times
MShaaban
1 year, 3 months ago
I thought the same. Agree with your approach.
upvoted 1 times
...
...
DASH_v
1 year, 6 months ago
Selected Answer: C
The most suitable privilege in this scenario would be administrative privileges on the web server. This is because the web server is responsible for hosting the web application and generating the application logs. By granting administrative privileges on the web server, the support team would be able to access the logs without having complete control over the underlying OS or other applications running on the same VM. Granting administrative privileges on the hypervisor or the OS would give the support team access to more than just the application logs, which could pose a security risk. Granting administrative privileges on the application folders alone may not provide the support team with enough access to view and analyze the logs.
upvoted 2 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
Jamati
2 years ago
Selected Answer: B
As Humongous1593 has already said. Least privilege rule applies.
upvoted 3 times
...
Coolwater
2 years, 1 month ago
A,C,D are managed by cloud vendor
upvoted 2 times
...
franbarpro
2 years, 1 month ago
Give them access to the only resources they need to do their job. No more no less!
upvoted 4 times
...
Humongous1593
2 years, 1 month ago
Selected Answer: B
Least privilege
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...