When adding several development interns who need limited access for a summer, which provisioning technique should be used?

Prepare for the CompTIA Cloud+ Exam with our comprehensive test. Enhance your skills with multiple choice questions, detailed hints, and explanations. Ace your test!

Multiple Choice

When adding several development interns who need limited access for a summer, which provisioning technique should be used?

Explanation:
Temporary access for a group of interns should be handled with identifiable identities and controlled permissions that end when the internship ends. The best approach is to create a role that contains only the permissions the interns need and grant each intern their own account that is a member of that role, with an expiration date set for the end of the summer. This setup supports the principle of least privilege, provides clear auditability because each intern has a unique identity, and makes revocation straightforward when the internship concludes. Other approaches compromise security and traceability. Sharing a single account prevents accurate auditing of actions and complicates revocation. Using a cloned or template account can blur accountability and may propagate permissions in unintended ways. And relying on a generic temporary group without individual accounts undermines traceability and access control.

Temporary access for a group of interns should be handled with identifiable identities and controlled permissions that end when the internship ends. The best approach is to create a role that contains only the permissions the interns need and grant each intern their own account that is a member of that role, with an expiration date set for the end of the summer. This setup supports the principle of least privilege, provides clear auditability because each intern has a unique identity, and makes revocation straightforward when the internship concludes.

Other approaches compromise security and traceability. Sharing a single account prevents accurate auditing of actions and complicates revocation. Using a cloned or template account can blur accountability and may propagate permissions in unintended ways. And relying on a generic temporary group without individual accounts undermines traceability and access control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy