An organization has experienced several data breaches over the last five years. These data breaches have cost the organization financially and damaged its reputation. The organization has hired a cybersecurity penetration team to perform a full security audit on the entire organization. This independent contractor conducted the audit and found the following vulnerabilities:
- Several user accounts allowed unauthorized and escalated privileges.
- Systems and information without formal authorization.
What two steps can the organization take to mitigate these risks? (Choose two.)
- log when elevated privileges are used
- assign the least privilege to perform the given task
- adopt a no reuse of passwords on different applications policy
- terminate access and reset all passwords
Related exam: Cybersecurity Essentials v3.0 Course Final Exam Answers
