Why is it recommended to use a separate administrative account for policy management versus day-to-day monitoring?
The principle of least privilege dictates that users should only have the permissions necessary to perform their job. Using separate accounts allows for granular assignment of roles, ensuring that monitoring accounts have read-only access, while policy-management accounts are restricted to essential personnel for critical configuration changes.
Why this answer
Separating administrative duties is a best practice to reduce the impact of account compromise. By using different accounts for different levels of access, an attacker who compromises a monitoring account will not necessarily have the permissions to modify security policies. This enhances the overall security posture and ensures that critical policy changes are performed by accounts with higher levels of scrutiny.
Exam trap
Many candidates confuse the principle of least privilege with operational convenience, incorrectly believing that using one account for all tasks simplifies audit logs and troubleshooting processes.