CompTIA Security+ (SY0-501) — Question 683
During a recent audit, it was discovered that several user accounts belonging to former employees were still active and had valid VPN permissions.
Which of the following would help reduce the amount of risk the organization incurs in this situation in the future?
Answer options
- A. Time-of-day restrictions
- B. User access reviews
- C. Group-based privileges
- D. Change management policies
Correct answer: B
Explanation
The correct answer, User access reviews, is essential for regularly verifying user accounts and their permissions, ensuring that only current employees have access. The other options, while useful in certain contexts, do not specifically address the need for ongoing oversight of user access rights.