Study. uk . com
  1. Home
  2. All questions
  3. Question 302

CompTIA Security+ study material · question 302 of 611

Which activity is designed to discover privilege creep?

  1. Periodic access review by the system owner
  2. Password rotation
  3. Session timeout enforcement
  4. Provisioning from an HR feed
Show the answer

Answer: A. Periodic access review by the system owner

Recertification asks whether each account still needs its access, which is how entitlements kept from old roles surface.

Source: NIST SP 800-53 Rev. 5 (NIST) — SP 800-53r5 › AC-2 Account Management

Challenge yourself on this topic → Study as cards