Soru

Zorluk: KolayIdentity and Access Management Operations

A security administrator receives an alert indicating that domain credentials belonging to a recently terminated employee were used to successfully log in to an internal server. Which of the following identity and access management (IAM) operational processes would have directly prevented this unauthorized access?

  1. Performing prompt account deprovisioning as part of the employee offboarding workflowCevap
  2. B
    Modifying discretionary access control permissions assigned to the user's role
  3. C
    Restricting server login access exclusively to users connected via the internal perimeter VPN
  4. D
    Deploying a detective SIEM correlation rule to log successful authentication events

Cevap

Performing prompt account deprovisioning during offboarding directly revokes authentication credentials, preventing terminated employees from logging in to network systems.
Account deprovisioning is an essential IAM operational process executed during offboarding to disable or remove user accounts immediately upon termination. Deactivating the account revokes identity rights and prevents former staff from authenticating to enterprise systems.

Adım Adım Çözüm

1
Identify the operational vulnerability presented in the scenario.
The issue is an active identity credential belonging to a terminated worker.
When employment is terminated, user credentials must immediately cease to be valid for authentication.
2
Evaluate the appropriate preventive IAM lifecycle procedure.
Automated or timely account deprovisioning deactivates access rights and credentials.
Deprovisioning directly revokes identity access privileges at the authentication source.

Anahtar Kavram

Identity Lifecycle Management and Account Deprovisioning
Bu soruyu puanla