Soru

Zorluk: OrtaIdentity and Access Management Operations

A security analyst at a healthcare organization is auditing authentication logs following a security alert. The logs reveal that an offboarded remote employee successfully accessed internal resources using legacy RADIUS credentials. Although the central identity provider (IdP) had disabled the employee's primary directory account, the RADIUS server accepted local fallback credentials because it failed to synchronize account deprovisioning status. Which of the following identity management operational practices would have MOST effectively prevented this unauthorized access?

  1. Implementing continuous identity lifecycle monitoring with automated directory synchronization and deprovisioning triggers.Cevap
  2. B
    Deploying a privileged access management (PAM) vault to manage standard remote user VPN sessions.
  3. C
    Configuring static network perimeter IP filtering rules to validate all inbound remote employee connections.
  4. D
    Enforcing resource authorization policies on the gateway prior to performing identity authentication checks.

Cevap

Implementing continuous identity lifecycle monitoring with automated directory synchronization and deprovisioning triggers.
Automated directory synchronization combined with robust identity lifecycle operational workflows ensures that when an account is disabled in the primary directory, the deprovisioning status is immediately propagated to all auxiliary authentication stores (such as RADIUS or TACACS+ local fallback databases).

Adım Adım Çözüm

1
Analyze the incident details from the authentication logs.
Identified that account revocation in the primary Identity Provider was not communicated to the local RADIUS database due to a synchronization failure.
Understanding the root cause is necessary to select the proper access control mitigation.
2
Evaluate the operational solution required to resolve missing account deprovisioning.
Continuous identity lifecycle workflows with automated deprovisioning sync ensure that account state changes apply globally across all identity repositories.
Proper identity lifecycle management prevents stale local accounts from remaining active after offboarding.

Anahtar Kavram

Identity Provisioning and Lifecycle Operations
Bu soruyu puanla