An organization has doubled in size due to a rapid market share increase. The size of the Information Technology (IT) staff has maintained pace with this growth. The organization hires several contractors whose onsite time is limited. The IT department has pushed its limits building servers and rolling out workstations and has a backlog of account management requests.
Which contract is BEST in offloading the task from the IT staff?
Answer : B
Identity as a Service (IDaaS) is the best contract in offloading the task of account management from the IT staff. IDaaS is a cloud-based service that provides identity and access management (IAM) functions, such as user authentication, authorization, provisioning, deprovisioning, password management, single sign-on (SSO), and multifactor authentication (MFA). IDaaS can help the organization to streamline and automate the account management process, reduce the workload and costs of the IT staff, and improve the security and compliance of the user accounts. IDaaS can also support the contractors who have limited onsite time, as they can access the organization's resources remotely and securely through the IDaaS provider.
The other options are not as effective as IDaaS in offloading the task of account management from the IT staff, as they do not provide IAM functions. Platform as a Service (PaaS) is a cloud-based service that provides a platform for developing, testing, and deploying applications, but it does not manage the user accounts for the applications. Desktop as a Service (DaaS) is a cloud-based service that provides virtual desktops for users to access applications and data, but it does not manage the user accounts for the virtual desktops. Software as a Service (SaaS) is a cloud-based service that provides software applications for users to use, but it does not manage the user accounts for the software applications.
An information technology (IT) employee who travels frequently to various ies remotely to an organization'
the following solutions BEST serves as a secure control mechanism to meet the organization's requirements?
to troubleshoot p Which of the following solutions BEST serves as a secure control mechanisn to meet the organization's requirements?
An organization implements a Remote Access Server (RAS). Once users correct to the server, digital certificates are used to authenticate their identity. What type of Extensible Authentication Protocol (EAP) would the organization use dring this authentication?
Answer : A
Transport layer security (TLS) is a type of Extensible Authentication Protocol (EAP) that the organization would use during this authentication. EAP is a framework that supports various methods of authentication for network access. TLS is one of the EAP methods that uses digital certificates to authenticate both the client and the server, and to establish a secure session key for encryption. TLS provides strong security, mutual authentication, and resistance to replay attacks. Reference: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Communication and Network Security, page 189; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4: Communication and Network Security, page 263]
Which of the following goals represents a modern shift in risk management according to National Institute of Standards and Technology (NIST)?
The security team has been tasked with performing an interface test against a frontend external facing application and needs to verify that all input fields protect against
invalid input. Which of the following BEST assists this process?
Internet Protocol (IP) source address spoofing is used to defeat
Which of the following MUST be done when promoting a security awareness program to senior management?