SY0-701 exam dumps

SY0-701 practice question 348 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 348

Single answerIdentity proofing

A healthcare company is rolling out a self-service process for issuing credentials to newly hired remote employees. HR provides basic onboarding data, but the security team has identified a risk that attackers could impersonate new hires and obtain valid accounts before the real employees start. The company wants to reduce this risk during enrollment without requiring every employee to appear on-site. Which control would BEST address this concern?

  1. A

    Require identity proofing during enrollment by validating a government-issued ID and performing a live remote verification step before issuing credentials

  2. B

    Require employees to change their passwords at first logon and enroll in security questions for account recovery

  3. C

    Issue temporary shared onboarding credentials to each department manager and let managers distribute them to new hires

  4. D

    Rely on the email address submitted by HR and send an activation link to that address as the only verification step

Show answer and explanation

Correct answer: A

Explanation

The best answer is the option that explicitly performs identity proofing before credential issuance. In Security+ terms, identity proofing is distinct from authentication and authorization. Authentication verifies a claimant to an existing account, while identity proofing establishes that the claimant is the legitimate person before the account is created or bound to credentials. For remote onboarding, organizations commonly use trusted evidence such as government-issued identification plus a supervised or automated remote verification workflow with liveness checks and document validation. This aligns with identity assurance best practices described in digital identity guidance such as NIST SP 800-63A, which covers identity proofing and enrollment. The other options improve convenience or account management but do not materially reduce the risk of impersonation during enrollment.

  • A. Correct.

    Correct. Identity proofing is the process of verifying that a person is who they claim to be before binding that identity to an account or credential. In this scenario, validating a trusted identity document and combining it with a live remote verification step, such as supervised video verification or liveness checking performed by an approved process, directly addresses the risk of impersonation during remote onboarding. This is stronger than simply trusting HR data or an email address because it establishes confidence in the real-world identity before credential issuance.

  • B. Incorrect.

    Incorrect. Requiring a password change at first logon improves password hygiene, and security questions are an account recovery mechanism, but neither verifies the person's identity before the account is issued. In fact, security questions are generally considered weak because answers may be guessable or discoverable. This option focuses on post-enrollment account security rather than identity proofing at enrollment.

  • C. Incorrect.

    Incorrect. Shared onboarding credentials reduce accountability and violate basic identity and access management principles, including individual accountability and non-repudiation. Even if managers are trusted, this approach increases the risk of unauthorized access and makes it difficult to prove which person used the credentials. It does not perform identity proofing of the individual new hire.

  • D. Incorrect.

    Incorrect. Sending an activation link to an email address supplied by HR is only a weak form of verification and does not sufficiently prove identity. If an attacker has access to the mailbox, or if the wrong address was entered, the attacker could still receive valid credentials. This is a common misconception: possession of an email account does not, by itself, establish high confidence in a person's real identity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam