Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: During an audit, it is discovered that several…

During an audit, it is discovered that several users have inherited permissions through nested group memberships that violate least privilege. What is the best approach to correct this?

⚠ Common exam trap

Test-takers frequently choose a one-time technical fix (like revoking all memberships) or a generic training option, failing to recognize that the CISSP exam emphasizes governance processes like periodic attestation as the sustainable solution for ongoing compliance with least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement periodic access reviews and attestation

Periodic access reviews and attestation (Option A) are the best approach because they establish a continuous governance process where data owners or managers formally confirm that inherited permissions from nested group memberships remain appropriate. This directly addresses the root cause—unchecked group nesting—by enforcing regular validation of access rights against the principle of least privilege, rather than relying on a one-time fix or training.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement periodic access reviews and attestation

    Why this is correct

    Implementing periodic access reviews and attestation directly addresses the discovery of excessive permissions by mandating regular validation. Managers or data owners review assigned access rights, including those inherited through nested groups, to confirm they align with current job functions and the principle of least privilege. This process requires explicit attestation, ensuring accountability for the continued necessity of each permission and facilitating the revocation of unnecessary access.

  • Re-certify group memberships quarterly

    Why it's wrong here

    While re-certifying group memberships quarterly verifies who belongs to a group, it fails to address the underlying issue of what permissions those groups, especially nested ones, actually grant. A user's effective permissions are often an aggregate of multiple group memberships, and simply confirming membership does not validate the appropriateness of the cumulative access rights. This approach overlooks the transitive nature of permissions, where a user might inherit excessive privileges through a group that is itself a member of another highly privileged group.

  • Provide training on least privilege

    Why it's wrong here

    Providing training on the principle of least privilege is a crucial proactive measure for fostering a security-aware culture and preventing future access violations. However, training alone does not remediate existing instances of excessive permissions that have already been discovered during an audit. It raises awareness about best practices but does not automatically revoke or adjust currently assigned, inappropriate access rights, which requires direct administrative action.

  • Revoke all group memberships and assign individually

    Why it's wrong here

    Revoking all group memberships and individually reassigning permissions is an extremely disruptive and inefficient approach to correcting excessive access. This drastic measure would halt operations, require extensive re-provisioning, and likely introduce new errors due to the sheer volume of manual work. A targeted review and revocation process, focusing only on identified excessive permissions, is far more practical and less impactful on business continuity.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.