A security analyst at a healthcare organization is auditing authentication logs following a security alert. The logs reveal that an offboarded remote employee successfully accessed internal resources using legacy RADIUS credentials. Although the central identity provider (IdP) had disabled the employee's primary directory account, the RADIUS server accepted local fallback credentials because it failed to synchronize account deprovisioning status. Which of the following identity management operational practices would have MOST effectively prevented this unauthorized access?
- Implementing continuous identity lifecycle monitoring with automated directory synchronization and deprovisioning triggers.Cevap
- BDeploying a privileged access management (PAM) vault to manage standard remote user VPN sessions.
- CConfiguring static network perimeter IP filtering rules to validate all inbound remote employee connections.
- DEnforcing resource authorization policies on the gateway prior to performing identity authentication checks.
Cevap
Implementing continuous identity lifecycle monitoring with automated directory synchronization and deprovisioning triggers.
Automated directory synchronization combined with robust identity lifecycle operational workflows ensures that when an account is disabled in the primary directory, the deprovisioning status is immediately propagated to all auxiliary authentication stores (such as RADIUS or TACACS+ local fallback databases).
Adım Adım Çözüm
Anahtar Kavram
Identity Provisioning and Lifecycle Operations