ExamGecko
Question list
Search
Search

Related questions

Question 139 - CISA discussion

Report
Export

In a 24/7 processing environment, a database contains several privileged application accounts with passwords set to never expire. Which of the following recommendations would BEST address the risk with minimal disruption to the business?

A.
Modify applications to no longer require direct access to the database.
Answers
A.
Modify applications to no longer require direct access to the database.
B.
Introduce database access monitoring into the environment
Answers
B.
Introduce database access monitoring into the environment
C.
Modify the access management policy to make allowances for application accounts.
Answers
C.
Modify the access management policy to make allowances for application accounts.
D.
Schedule downtime to implement password changes.
Answers
D.
Schedule downtime to implement password changes.
Suggested answer: B

Explanation:

The best recommendation to address the risk of privileged application accounts with passwords set to never expire in a 24/7 processing environment is to introduce database access monitoring into the environment. Database access monitoring is a security control that tracks and records all activities and transactions performed on a database, especially by privileged users or accounts. Database access monitoring can help address the risk of privileged application accounts with passwords set to never expire by detecting and alerting any unauthorized or abnormal access or actions on the database. The other options are not as effective as database access monitoring in addressing the risk, as they may cause disruption to the business or violate the access management policy. Modifying applications to no longer require direct access to the database is a complex and costly solution that may affect the functionality or performance of the applications, and it may not be feasible or practical in a 24/7 processing environment. Modifying the access management policy to make allowances for application accounts is a risky solution that may create exceptions or loopholes in the policy, and it may not comply with the best practices or standards for password management. Scheduling downtime to implement password changes is a disruptive solution that may affect the availability or continuity of the systems or applications, and it may not be acceptable or possible in a 24/7 processing environment.Reference:CISA Review Manual (Digital Version), Chapter 5, Section 5.2.4

asked 18/09/2024
Karol Ligęza
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first