ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is writing security requirements for an IAM service. To enforce least privilege when employees transfer to a new department, what technical requirement should be included in the data access provisioning section?
Log all authentication attempts to a centralized SIEM in near real time.
Require privileged service accounts to store their secrets in a hardware security module.
Enforce multi-factor authentication for interactive administrator logins.
Integrate the provisioning engine with the HR system so that role changes automatically trigger revocation of previous entitlements and assignment of new ones.
Linking the provisioning engine directly to the authoritative HR data source ensures that any change of employment status-such as a departmental transfer-automatically revokes obsolete entitlements and grants only the permissions needed for the new role. This fulfills least-privilege principles and meets audit expectations for prompt access adjustment. Storing service-account secrets in an HSM, enhanced logging, and MFA for administrators are valuable controls, but they do not specifically address timely privilege changes following a role transition.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an IAM service?
Open an interactive chat with Bash
What does 'least privilege' mean in security?
Open an interactive chat with Bash
What is the role of a provisioning engine in IAM?
Open an interactive chat with Bash
What is an IAM service?
Open an interactive chat with Bash
What is the principle of least privilege?
Open an interactive chat with Bash
How does integrating the provisioning engine with the HR system enforce least privilege?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .