Soru

Zorluk: OrtaIdentity and Access Management Operations

A security analyst is conducting a routine audit of Identity and Access Management (IAM) operational logs following an employee offboarding procedure. The log analysis reveals that an offboarded engineer's primary user account was disabled in Active Directory immediately upon termination. However, three days later, successful interactive logins were recorded on several internal servers using a secondary administrative account assigned to the same individual. Which of the following identity management operational failures is the MOST likely root cause of this security gap?

  1. Incomplete account lifecycle deprovisioning across secondary and privileged identities.Cevap
  2. B
    Failure to configure appropriate Role-Based Access Control (RBAC) permission boundaries.
  3. C
    Absence of a network perimeter firewall blocking remote management traffic.
  4. D
    Undetected pass-the-hash attacks targeting single sign-on authentication tokens.

Cevap

Incomplete account lifecycle deprovisioning across secondary and privileged identities.
Comprehensive identity lifecycle management requires all accounts associated with an individual—including primary, secondary, and privileged administrative accounts—to be promptly identified and deprovisioned during employee offboarding. Leaving secondary accounts active creates orphaned accounts that present critical security vulnerabilities.

Adım Adım Çözüm

1
Analyze the incident details from the IAM operational log audit.
Identified that while the primary user account was disabled during offboarding, a secondary administrative account assigned to the same user remained active.
Offboarding procedures must track and revoke all identities linked to an individual.
2
Evaluate the cause of the unauthorized post-offboarding logins.
The logins succeeded because valid credentials for the secondary account were still active in the environment.
Orphaned accounts resulting from partial deprovisioning remain fully functional for authentication.
3
Determine the operational failure responsible for the security gap.
The root cause is incomplete identity lifecycle management during account deprovisioning.
Effective IAM operations require comprehensive account inventory and complete deprovisioning workflows across all user identities.

Anahtar Kavram

Identity Lifecycle Management and Account Deprovisioning Operations
Bu soruyu puanla