Exam 212-89 Topic 6 Question 156 Discussion
Actual exam question for EC-COUNCIL's 212-89 exam
Question #: 156
Topic #: 6
Question #: 156
Topic #: 6
Sophia, a security analyst, notices that a sensitive folder on a file server was accessed during off- hours by an intern using authorized credentials. The access was not flagged because the intern's permissions had not been reviewed in months after their project ended. What process should have been enforced to avoid this insider threat?
Suggested Answer: C Vote an answer
The EC-Council Incident Handler (ECIH) curriculum stresses that periodic access reviews are essential for preventing insider threats. When user roles change or projects end, permissions must be reviewed and adjusted according to the Principle of Least Privilege (PoLP).
In this case, the intern retained access privileges beyond the project duration due to lack of periodic auditing. Regular auditing of user access rights ensures that permissions remain aligned with job responsibilities and reduces the risk of privilege misuse.
In this case, the intern retained access privileges beyond the project duration due to lack of periodic auditing. Regular auditing of user access rights ensures that permissions remain aligned with job responsibilities and reduces the risk of privilege misuse.
by Quintion at Oct 04, 2026, 11:30 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).