CompTIA Security+ (SY0-601) — Question 213

As part of annual audit requirements, the security team performed a review of exceptions to the company policy that allows specific users the ability to use USB storage devices on their laptops. The review yielded the following results:

• The exception process and policy have been correctly followed by the majority of users.
• A small number of users did not create tickets for the requests but were granted access.
• All access had been approved by supervisors.
• Valid requests for the access sporadically occurred across multiple departments.
• Access, in most cases, had not been removed when it was no longer needed.

Which of the following should the company do to ensure that appropriate access is not disrupted but unneeded access is removed in a reasonable time frame?

Answer options

Correct answer: C

Explanation

The correct answer, C, involves a thorough quarterly audit which ensures that all exceptions are reviewed and validated by management, thus allowing for the removal of unnecessary access effectively. Option A is flawed as it relies solely on supervisor denial, which may not capture all unneeded access. Option B is too extreme, removing access for all employees without considering existing valid approvals. Option D, while useful for tracking, does not ensure that unneeded access is promptly revoked.