ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 278 - SY0-701 discussion

Report
Export

A security audit of an organization revealed that most of the IT staff members have domain administrator credentials and do not change the passwords regularly. Which of the following solutions should the security learn propose to resolve the findings in the most complete way?

A.
Creating group policies to enforce password rotation on domain administrator credentials
Answers
A.
Creating group policies to enforce password rotation on domain administrator credentials
B.
Reviewing the domain administrator group, removing all unnecessary administrators, and rotating all passwords
Answers
B.
Reviewing the domain administrator group, removing all unnecessary administrators, and rotating all passwords
C.
Integrating the domain administrator's group with an IdP and requiring SSO with MFA for all access
Answers
C.
Integrating the domain administrator's group with an IdP and requiring SSO with MFA for all access
D.
Securing domain administrator credentials in a PAM vault and controlling access with role-based access control
Answers
D.
Securing domain administrator credentials in a PAM vault and controlling access with role-based access control
Suggested answer: D

Explanation:

Using a Privileged Access Management (PAM) vault to secure domain administrator credentials and enforcing role-based access control (RBAC) is the most comprehensive solution. PAM systems help manage and control access to privileged accounts, ensuring that only authorized personnel can access sensitive credentials. This approach also facilitates password rotation, auditing, and ensures that credentials are not misused or left unchanged. Integrating PAM with RBAC ensures that access is granted based on the user's role, further enhancing security.

Reference =

CompTIA Security+ SY0-701 Course Content: Domain 05 Security Program Management and Oversight.

CompTIA Security+ SY0-601 Study Guide: Chapter on Identity and Access Management.

asked 02/10/2024
Maurice Nicholson
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first