Exam 212-89 Topic 6 Question 156 Discussion

Actual exam question for EC-COUNCIL's 212-89 exam
Question #: 156
Topic #: 6
Sophia, a security analyst, notices that a sensitive folder on a file server was accessed during off- hours by an intern using authorized credentials. The access was not flagged because the intern's permissions had not been reviewed in months after their project ended. What process should have been enforced to avoid this insider threat?

Suggested Answer: C Vote an answer

The EC-Council Incident Handler (ECIH) curriculum stresses that periodic access reviews are essential for preventing insider threats. When user roles change or projects end, permissions must be reviewed and adjusted according to the Principle of Least Privilege (PoLP).
In this case, the intern retained access privileges beyond the project duration due to lack of periodic auditing. Regular auditing of user access rights ensures that permissions remain aligned with job responsibilities and reduces the risk of privilege misuse.

by Quintion at Oct 04, 2026, 11:30 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10