exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 309 discussion

Actual exam question from CompTIA's CAS-004
Question #: 309
Topic #: 1
[All CAS-004 Questions]

A company is designing a new system that must have high security. This new system has the following requirements:

• Permissions must be assigned based on role.
• Fraud from a single person must be prevented.
• A single entity must not have full access control.

Which of the following can the company use to meet these requirements?

  • A. Dual responsibility
  • B. Separation of duties
  • C. Need to know
  • D. Least privilege
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Steel16
2 months, 1 week ago
Selected Answer: D
o D. Least privilege: to meet the security requirements of assigning permissions based on role, preventing fraud from a single person, and ensuring no single entity has full access control. This security principle means granting users only the minimum level of access needed to perform their job functions, effectively limiting their ability to access sensitive data or perform unauthorized actions. o B. Separation of duties: While important for preventing fraud, it might not fully address the requirement of limiting access for individual users. Separation of duties ensures that critical tasks are handled by different people, but it doesn't necessarily restrict individual user access to sensitive data if they have the necessary role-based permissions.
upvoted 1 times
...
EAlonso
9 months, 4 weeks ago
B. agree, it implies all the requirements.
upvoted 2 times
...
CXSSP
1 year, 8 months ago
Selected Answer: B
B. Separation of duties The company can use the concept of Separation of Duties to meet these requirements. Here's how each requirement aligns with Separation of Duties: Permissions based on role: Separation of Duties ensures that permissions and responsibilities are divided among multiple individuals or roles. This means that different roles will have different sets of permissions based on their responsibilities. Preventing fraud from a single person: By separating critical tasks or functions, it becomes more difficult for a single individual to carry out fraudulent activities without detection. This helps to mitigate the risk of fraud. Preventing a single entity from having full access control: Separation of Duties ensures that no single entity or individual has full control or authority over all aspects of a system or process. This reduces the risk of misuse or abuse of privileges.
upvoted 4 times
...
Uncle_Lucifer
1 year, 8 months ago
Separation of duties for sure!
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago