hardMultiple ChoiceObjective-mapped
CISSP Practice Question: During an audit, it is discovered that several…
During an audit, it is discovered that several users have inherited permissions through nested group memberships that violate least privilege. What is the best approach to correct this?
⚠ Common exam trap
Test-takers frequently choose a one-time technical fix (like revoking all memberships) or a generic training option, failing to recognize that the CISSP exam emphasizes governance processes like periodic attestation as the sustainable solution for ongoing compliance with least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement periodic access reviews and attestation
Periodic access reviews and attestation (Option A) are the best approach because they establish a continuous governance process where data owners or managers formally confirm that inherited permissions from nested group memberships remain appropriate. This directly addresses the root cause—unchecked group nesting—by enforcing regular validation of access rights against the principle of least privilege, rather than relying on a one-time fix or training.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement periodic access reviews and attestation
Why this is correct
Implementing periodic access reviews and attestation directly addresses the discovery of excessive permissions by mandating regular validation. Managers or data owners review assigned access rights, including those inherited through nested groups, to confirm they align with current job functions and the principle of least privilege. This process requires explicit attestation, ensuring accountability for the continued necessity of each permission and facilitating the revocation of unnecessary access.
- ✗
Re-certify group memberships quarterly
Why it's wrong here
While re-certifying group memberships quarterly verifies who belongs to a group, it fails to address the underlying issue of what permissions those groups, especially nested ones, actually grant. A user's effective permissions are often an aggregate of multiple group memberships, and simply confirming membership does not validate the appropriateness of the cumulative access rights. This approach overlooks the transitive nature of permissions, where a user might inherit excessive privileges through a group that is itself a member of another highly privileged group.
- ✗
Provide training on least privilege
Why it's wrong here
Providing training on the principle of least privilege is a crucial proactive measure for fostering a security-aware culture and preventing future access violations. However, training alone does not remediate existing instances of excessive permissions that have already been discovered during an audit. It raises awareness about best practices but does not automatically revoke or adjust currently assigned, inappropriate access rights, which requires direct administrative action.
- ✗
Revoke all group memberships and assign individually
Why it's wrong here
Revoking all group memberships and individually reassigning permissions is an extremely disruptive and inefficient approach to correcting excessive access. This drastic measure would halt operations, require extensive re-provisioning, and likely introduce new errors due to the sheer volume of manual work. A targeted review and revocation process, focusing only on identified excessive permissions, is far more practical and less impactful on business continuity.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.