When a security audit is performed at a company, the auditor reports that new users have access to network resources beyond their normal job roles. Additionally, users who move to different positions retain their prior permissions. What kind of violation is occurring?
- password
- network policy
- least privilege
- audit
Explanation: Users should have access to information on a need to know basis. When a user moves from job role to job role, the same concept applies.
Related exam: IT Essentials 8.0 Practice Final Exam Modules 10-14
Related exam: Checkpoint Exam: Network Defense Group Exam
Related exam: Network Defense - 3.5.2 Module 3: Access Control Quiz
