A company is designing a new system that must have high secu - CompTIA CAS-005

Question

A company is designing a new system that must have high security. This new system has the following requirements:

  • Permissions must be assigned based on role.
  • Fraud from a single person must be prevented.
  • A single entity must not have full access control.

Which of the following can the company use to meet these requirements?

Answers
  1. correct
Explanation

The correct answer is: B. Separation of duties

Separation of duties is a security principle designed to prevent fraud and reduce the risk of errors or malicious actions by ensuring that no single person has complete control over a critical process or system. In this case:

  1. Permissions assigned based on role: Separation of duties aligns with role-based access control (RBAC), where different roles are assigned specific permissions to avoid overlapping responsibilities.
  2. Fraud prevention: By dividing responsibilities among multiple individuals, no single person has enough access or authority to commit fraud without collusion.
  3. No single entity with full control: Separation of duties ensures that critical actions (e.g., authorizing, executing, and reviewing transactions) are distributed among multiple roles.

Why the other options are incorrect:

Dual responsibility:

  • Incorrect: Dual responsibility requires two people to perform a task together, which is related but does not directly implement role-based permissions or address separation of critical responsibilities.

Need to know:

  • Incorrect: Need to know restricts access to information based on what is necessary for a role or task but does not explicitly prevent full access control or address the division of responsibilities.

Least privilege:

  • Incorrect: Least privilege ensures that users only have the minimum permissions needed to perform their tasks. While important for security, it does not explicitly address dividing responsibilities or preventing fraud from a single individual.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered