exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 1053 discussion

Actual exam question from CompTIA's SY0-501
Question #: 1053
Topic #: 1
[All SY0-501 Questions]

A security administrator has been conducting an account permissions review that has identified several users who belong to functional groups and groups responsible for auditing the functional groups' actions. Several recent outages have not been able to be traced to any user. Which of the following should the security administrator recommend to preserve future audit log integrity?

  • A. Enforcing stricter onboarding workflow policies
  • B. Applying least privilege to user group membership
  • C. Following standard naming conventions for audit group users
  • D. Restricting audit group membership to service accounts
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ID77
1 year, 3 months ago
Selected Answer: B
Following standard naming conventions for audit group users may help in organizing and identifying users within audit groups, but it doesn't directly address the issue of preserving audit log integrity or enhancing accountability as effectively as applying least privilege.
upvoted 1 times
...
Steve107
4 years ago
Audit group needs read only permission, function group needs change permission. Mix together hurts the least privilege.
upvoted 2 times
...
monkeyyyyy
4 years ago
Several users who belong to functional groups and groups responsible for auditing the functional groups actions -> these users could audit their own accounts and maybe change something and then remove the trace -> damage the integrity of the log How could standard naming convention avoid this? I think a more reasonable way is to remove these users from the audit group so that they couldn't audit their own accounts anymore -> deprive some of their permissions/privileges so that the integrity of the audit log can be preserved. And the closest option we have seems like to be B - apply the least privilege
upvoted 4 times
...
Dion79
4 years ago
A standard naming convention allows better administrative control over network resources. The naming strategy should allow administrators to identify the type and function of any particular resource or location at any point in the directory information tree. Using Active Directory as an example, one of the first decisions is to determine how your AD namespace will integrate with your public DNS records. For example, you may make the AD namespace a delegated subdomain of your public DNS domain name (for example, ad.widget.com). This solution isolates AD from the public Internet and means that the DNS servers supporting the public domain name (widget.com) do not need to support Active Directory. User account names are usually either based on the firstname.lastname format (bob.dobbs), or a combination of first or first and second initial with lastname (jrdobbs). Accounts should be named in a consistent manner. This helps facilitate management of accounts, especially through scripting and command-line usage. You should also refrain from naming accounts based on nicknames or common words so as not to anonymize users.
upvoted 3 times
...
Lobizon
4 years, 1 month ago
C is more right than the others. Biggest issue is outages not being able to trace to any user. For this review of permissons, the security analyst must be seeing something wrong in the naming conventions or why the group permissions are overlapping this way. I eliminate least privelegd because I assume least priveledge is already implemented and still have outtages. I also eliminate D 'cause service accounts are for machine2machines not people..
upvoted 1 times
...
twander78
4 years, 1 month ago
vote for B
upvoted 1 times
...
Heymannicerouter
4 years, 1 month ago
"users who belong to functional groups and groups responsible for auditing the functional groups' actions", need to apply least privilege here.
upvoted 3 times
suje
4 years, 1 month ago
This doesn't solve the issue because you'll still have users on both groups, applying 'least privilege' won't change that. You can't have the same people that apply the changes to audit them that's a security issue because they can make a change and erase any trace of that change.
upvoted 2 times
madaraamaterasu
4 years, 1 month ago
So you it's D then?
upvoted 1 times
...
...
...
cyberzzz
4 years, 1 month ago
Also vote for D
upvoted 2 times
...
madaraamaterasu
4 years, 1 month ago
Shouldn't it be D?
upvoted 2 times
Heymannicerouter
4 years, 1 month ago
No, service accounts are for applications/services only. It should be B imo.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...