Free CompTIA PenTest+ PT0-002 Practice Question

A penetration test for a retail organization with multiple physical locations reveals that certain branch managers have the ability to grant themselves higher privileges in the corporate network, potentially enabling access to sensitive customer data. Considering the separation of duties and mitigation of insider threat, what operational control should be recommended in the report to address this finding?

  • Implement role-based access control to enforce separation of duties.

  • Set up time-of-day restrictions on when branch managers can access the network.

  • Implement multifactor authentication for sensitive systems access.

  • Enforce mandatory vacations for branch managers to identify inappropriate system dependencies.

This question's topic:
CompTIA PenTest+ PT0-002 / 
Reporting and Communication
Your Score:

Check or uncheck an objective to set which questions you will receive.