ExamGecko
Question list
Search
Search

Related questions

Question 2 - CISA discussion

Report
Export

Which of the following is the BEST way to enforce the principle of least privilege on a server containing data with different security classifications?

A.
Limiting access to the data files based on frequency of use
Answers
A.
Limiting access to the data files based on frequency of use
B.
Obtaining formal agreement by users to comply with the data classification policy
Answers
B.
Obtaining formal agreement by users to comply with the data classification policy
C.
Applying access controls determined by the data owner
Answers
C.
Applying access controls determined by the data owner
D.
Using scripted access control lists to prevent unauthorized access to the server
Answers
D.
Using scripted access control lists to prevent unauthorized access to the server
Suggested answer: C

Explanation:

The best way to enforce the principle of least privilege on a server containing data with different security classifications is to apply access controls determined by the data owner. The principle of least privilege states that users should only have the minimum level of access required to perform their tasks. The data owner is the person who has the authority and responsibility to classify, label, and protect the data according to its sensitivity and value. The data owner can define the access rights and permissions for each user or role based on the data classification policy and the business needs. This will ensure that only authorized and appropriate users can access the data and prevent unauthorized or excessive access that could compromise the confidentiality, integrity, or availability of the data.Reference:

CISA Review Manual (Digital Version)

CISA Questions, Answers & Explanations Database

asked 18/09/2024
Geetanjali Singh
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first