312-50 exam dumps

312-50 practice question 14 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 14

Single answer▪ Information Security Controls

A financial services company allows third-party contractors to remotely administer a set of Linux servers that store sensitive customer data. During a security review, you discover that contractors connect over VPN using shared administrator credentials, and activity logs only show the generic admin account. Management wants a control that reduces the risk of unauthorized use and ensures each administrative action can be traced to an individual without significantly disrupting operations. Which information security control is the MOST appropriate to recommend first?

  1. A

    Implement named individual administrator accounts with centralized authentication and require MFA for privileged access

  2. B

    Increase VPN session timeout values so contractors must reconnect more often

  3. C

    Deploy full-disk encryption on the Linux servers to ensure administrative accountability

  4. D

    Disable remote administration and require all contractors to work on-site only

Show answer and explanation

Correct answer: A

Explanation

The scenario focuses on two core security objectives: preventing unauthorized privileged access and ensuring accountability for administrative actions. Shared accounts undermine nonrepudiation, auditability, and incident investigation because multiple users can perform actions under the same identity. The most appropriate first control is to assign each contractor a unique named account, authenticate them centrally, and require MFA for privileged access. This combination provides a strong preventive control against credential abuse and a detective capability through accurate logs tied to an individual. This approach is consistent with established best practices in NIST SP 800-53, including IA-family controls for identification and authentication, AC-family controls for access enforcement, and AU-family controls for audit records. In practical terms, organizations often pair this with role-based access control, privileged access management, and log forwarding to a SIEM, but the foundational correction is eliminating shared privileged credentials.

  • A. Correct.

    This is the best answer because it directly addresses both identification/accountability and unauthorized use of privileged access. Replacing shared administrator credentials with unique named accounts enables individual accountability through audit logs, and centralized authentication improves lifecycle management such as rapid revocation when a contractor leaves. Adding MFA strengthens the preventive control by reducing the risk of credential compromise. This aligns with the principle of accountability and least privilege found in common guidance such as NIST SP 800-53 controls for identification/authentication and auditability.

  • B. Incorrect.

    This is incorrect because shortening or increasing reconnect frequency does not solve the core problem of shared credentials and lack of user attribution. Session timeout settings may have some value as a supplemental session management control, but they do not create individual accountability in logs and do little to prevent misuse by someone already using a shared account.

  • C. Incorrect.

    This is incorrect because full-disk encryption is primarily a protective control for data at rest, especially against offline access after device theft or improper disposal. It does not identify which contractor performed an administrative action, nor does it prevent misuse of shared privileged credentials during normal system operation. A candidate might choose this because the servers hold sensitive data, but the scenario is specifically about traceability and access accountability.

  • D. Incorrect.

    This is incorrect because it is an overly disruptive administrative restriction and does not inherently provide accountability if shared credentials remain in use on-site. Physical presence is not a substitute for proper logical access controls, unique identification, and authentication. It may reduce some remote attack exposure, but it is not the most appropriate first control for the stated problem.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam