exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 110 discussion

Actual exam question from CompTIA's SY0-501
Question #: 110
Topic #: 1
[All SY0-501 Questions]

A manager suspects that an IT employee with elevated database access may be knowingly modifying financial transactions for the benefit of a competitor. Which of the following practices should the manager implement to validate the concern?

  • A. Separation of duties
  • B. Mandatory vacations
  • C. Background checks
  • D. Security awareness training
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Stefanvangent
Highly Voted 5 years, 11 months ago
Shouldn't the answer be B? Separation of duties would prevent fraud but not detect it .Mandatory vacations would detect malicious activity when it occurs.
upvoted 26 times
...
billie
Highly Voted 5 years, 10 months ago
A because IT and Finance are different duties
upvoted 15 times
wwwwwsr
4 years, 4 months ago
good answer
upvoted 1 times
...
FNavarro
4 years, 4 months ago
So they should hire a financier to manage their database? Hmmmm....
upvoted 6 times
...
...
LB54
Most Recent 3 years, 12 months ago
The question is: Which of the following practices should the manager implement to validate the concern? So the concern is there and now that need to validate/disprove it... Mandatory vacations - would a lot the company time to audit his work and discover/validate the concern. Separation of duties - would be able to prevent this from occurring in the future. B. Mandatory vacations
upvoted 6 times
...
iHungover
4 years, 1 month ago
If you send the suspected insider on a vacation (implementing mandatory vacation for all employees) and the transactions stop then you will have validate the suspicions of the insider threat actor
upvoted 2 times
...
Vero00
4 years, 2 months ago
Separation of Duties would prevent this to happend, what it's needed here is to "validate the concern", Mandatory Vacations are used to detect fraud, or suspicious activity.
upvoted 2 times
...
MortG7
4 years, 4 months ago
It is separation of duties...IT guy with DB permissions...separation of duties would revoke his DB access and only grant to DB admins.
upvoted 3 times
...
Miltduhilt
4 years, 5 months ago
"knowingly modifying" key word. A. Separation of Duties Separation of duties -- is a means of establishing checks and balances against the possibility that critical systems or procedures can be compromised by insider threats. Separation of duties states that no one person should have too much power or responsibility. Duties and responsibilities should be divided among individuals to prevent ethical conflicts or abuse of powers. Duties such as authorization and approval and design and development should not be held by the same individual, because it would be far too easy for that individual to exploit an organization into using only specific software that contains vulnerabilities or taking on projects that would be beneficial to that individual.
upvoted 2 times
LB54
3 years, 12 months ago
valid point but not the question posed. Not trying to figure out how to prevent it from happening. The question only seems to be how to validate the concern that the employee is doing what they suspect him of doing... Which would be mandatory vacations so that employee's work could be audited. after which I'm sure they will want to implement separation of duties.
upvoted 3 times
...
...
who__cares123456789___
4 years, 6 months ago
Lead2Pass, boasting 96% accuracy and verified by Security Professionals and charging me 100$ says "B Mandatory Vacay"...going w B!! Final Answer!!
upvoted 4 times
...
exiledwl
4 years, 6 months ago
It's def B. Seperation of duties can't necessary validate the concern. Mandatory vacations are designed to discover fraud wrongdoing etc
upvoted 3 times
...
WillGTechDaily
4 years, 8 months ago
They need to start putting these answers together as both Seperation of duties and Mandatory Vacations helps detect fraud , this test is starting to piss me off. Comptia stop putting answers on test like this. I'm going to let them know how I feel about this on the comments section of the test.
upvoted 6 times
...
DW_2020
4 years, 9 months ago
It is possible that all this companies IT personnel may have this access, so mandatory vacations wouldn't solve this. What this problem needs is for IT to only have access to financial databases when needed, ideally 'least privilege' but also separation of duties, which would possibly allocate a DB Admin role, not accessible to all IT personnel, and only granted for specific issue resolution.
upvoted 1 times
...
Hanzero
4 years, 10 months ago
Has to be B. If he has elevated access, that won't prevent him from accessing the database even if seperation of duties occurred. If he is on vacation, then we'll know who's modifying the transactions.
upvoted 1 times
...
Andy2929
4 years, 10 months ago
This is definitely Mandatory Vacations so that the Manager can detect/ investigate on the issue.
upvoted 1 times
...
robopips
4 years, 11 months ago
Even if there was a separation of duties, if the IT has elevated DB access, he can always access the financial transactions no matter what. I think B is the correct answer here. Let him have a mandatory vacation and check records for validation.
upvoted 1 times
...
Kudojikuto
4 years, 12 months ago
I think B is correct
upvoted 1 times
...
Ch3er1o
5 years ago
The thing here is validation. The manager needs to validate his concern therefore a mandatory vacation would identify the validity of the managers suspicion.
upvoted 2 times
...
Jo3
5 years ago
Separation of duties policies also apply to IT personnel. As an example, a group of IT administrators may be assigned responsibility for maintaining a group of database servers. However, they would not be granted access to security logs on these servers. Instead, security administrators regularly review these logs, but these security administrators will not have access to data within the databases. Darril Gibson CompTIA Security+ SY0-501 Study Guide
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...