Certified In Cybersecurity CC · Free Practice Question Easy
Question 32
ThorTeaches.com has recently undergone a merger and acquisition, resulting in a significant increase in the number of employees and access points to the company's network and systems. As the IT security manager, you are responsible for ensuring the security of the company's data and systems. What is the best practice for de-provisioning employee access to the company's network and systems?
- A Implementing a multi-factor authentication system
- B Reviewing and revoking access rights on a weekly basis
- C Terminating employee access immediately upon termination of employment
- D Waiting 30 days after termination of employment to terminate employee access
Reveal correct answer
Correct answer: C
Explanation
The correct answer: Terminating employee access immediately upon termination of employment: When an employee leaves a company, it is a best practice to terminate their access to the company's systems and data immediately. This is done to protect the company's information and systems from unauthorized access and potential misuse. Even if the employee leaves on good terms, there is still a risk associated with the potential for their credentials to be compromised. Therefore, the immediate termination of access helps to minimize this risk. This approach also aligns with the principle of least privilege, which suggests that individuals should only have the access necessary to perform their job functions and no more. The incorrect answers: Waiting 30 days after termination of employment to terminate employee access: Waiting for 30 days after an employee's termination to revoke their access is a poor security practice. During this period, the former employee still has the potential to access sensitive company data and systems, which could lead to data breaches, intellectual property theft, or other security incidents. Even if the employee does not have malicious intent, their account could be compromised by a third party during this period. Reviewing and revoking access rights on a weekly basis: While regular reviews of access rights is a good security practice, this approach is not sufficient for managing the deprovisioning of employee access. When an employee leaves the company, their access should be terminated immediately, not during the next scheduled review. Waiting until the next review cycle would leave a window of time during which the former employee could still potentially access company systems and data. Implementing a multi-factor authentication system: While multi-factor authentication is a critical component of a robust security program and can help protect against unauthorized access, it doesn't directly address the deprovisioning of access when an employee leaves the company. An ex-employee's account with multi-factor authentication is still a potential security risk if not deactivated immediately upon termination. Furthermore, this option is more about enhancing access control measures for current employees rather than managing the access of departing ones.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
