CompTIA CASP+ (CAS-004) — Question 33
A university issues badges through a homegrown identity management system to all staff and students. Each week during the summer, temporary summer school students arrive and need to be issued a badge to access minimal campus resources. The security team received a report from an outside auditor indicating the homegrown system is not consistent with best practices in the security field and leaves the institution vulnerable.
Which of the following should the security team recommend FIRST?
Answer options
- A. Investigating a potential threat identified in logs related to the identity management system
- B. Updating the identity management system to use discretionary access control
- C. Beginning research on two-factor authentication to later introduce into the identity management system
- D. Working with procurement and creating a requirements document to select a new IAM system/vendor
Correct answer: D
Explanation
The correct answer is D because selecting a new IAM system/vendor addresses the vulnerabilities highlighted in the audit report by ensuring a more secure and compliant solution is put in place. Options A, B, and C do not resolve the fundamental issues with the existing system and merely address symptoms rather than the root cause of the security concerns.