Knowee
Questions
Features
Study Tools

A company implements an Internet-facing web server for its sales force to review product information. The sales force can also update its profiles and profile photos, but not the product information. There is no other information on this server.Which content access permissions should be granted to the sales force based on the principle of least privilege? Read and write access Limited write access only Limited read access only Read and limited write access

Question

A company implements an Internet-facing web server for its sales force to review product information. The sales force can also update its profiles and profile photos, but not the product information. There is no other information on this server.Which content access permissions should be granted to the sales force based on the principle of least privilege? Read and write access Limited write access only Limited read access only Read and limited write access

...expand
🧐 Not the exact question you are looking for?Go ask a question

Solution

The sales force should be granted "Read and limited write access". This is because they need to be able to view (read) the product information and update (write) their own profiles and profile photos. However, they should not have full write access as they do not need to, and should not be able to, update the product information. This follows the principle of least privilege, which states that users should be given the minimum levels of access necessary to complete their tasks.

This problem has been solved

Similar Questions

Rebecca, a security professional, was instructed to limit employees’ access to critical resources. For this purpose, she implemented an access principle that provides permission to access only necessary resources that are required for their job tasks. The permissions can be extended later based on changes in their job roles. Identify the access principle implemented by Rebecca in the above scenario.Group of answer choicesPrinciple of least privilege (POLP)Rule-based access controlNeed-to-knowSeparation of duties (SoD)

Which of the following access control approaches provides the ability to share resources or information in a peer-to-peer configuration?Group of answer choicesRole-basedDiscretionaryNon-DiscretionaryMandatory

You are a network administrator implementing access controls in a financial institution. The CEO has requested unrestricted access to all systems and sensitive data to facilitate their decision-making process. What is the most appropriate approach to granting access while maintaining security?1.0 MarksGrant the CEO temporary access to specific systems and data upon request Grant the CEO unrestricted access as requestedGrant the CEO read-only access to sensitive data and limit their administrative privilegesProvide the CEO with a separate network segment for unrestricted accessImplement strict access controls and monitor the CEO's activities closely

What are the default SharePoint permissions levels?

Which of the following is a privilege or action that can be taken on a system?answerDACLPermissionsSACLUser rights

1/1

Upgrade your grade with Knowee

Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.