Associate Cloud Workspace Administrator · Free Practice Question Medium
Question 15
Your organization has a strict security policy that restricts most IT personnel from accessing security-related settings. However, the IT team needs to manage user accounts (including creation and deletion) and reset passwords without having access to security controls or billing information. What is the best approach to ensure IT team members have only the necessary permissions?
-
A
Assign them the Help Desk Admin role
-
B
Assign them the Super Admin role since it provides all needed permissions
-
C
Create a custom administrator role with only user management and password reset privileges
-
D
Assign them the User Management Admin role
Reveal correct answer
Correct answer: C
Explanation
Create a custom administrator role with only user management and password reset privileges -> Correct. Custom roles allow fine-tuning of permissions, ensuring IT team members only receive access to necessary functionalities. By creating a custom role that includes user creation, deletion, and password resets while excluding security settings, this approach follows the principle of least privilege and meets the security policy requirements.
Assign them the Super Admin role since it provides all needed permissions -> Incorrect. The Super Admin role grants full access to all settings, including security policies, application configurations, and billing. This level of control is unnecessary for an IT team focused on user management. Granting excessive privileges increases security risks and violates the principle of least privilege.
Assign them the User Management Admin role -> Incorrect. While the User Management Admin role allows user account management (creation, deletion, and updates), it also provides access to move users between organizational units, which may not be necessary. If more granular control is needed, a custom role is a better option.
Assign them the Help Desk Admin role -> Incorrect. The Help Desk Admin role is limited to password resets and basic user support but does not allow user creation or deletion, which is required for the IT team in this scenario.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
