312-50 exam dumps

312-50 practice question 15 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 15

Single answer▪ Information Security Controls

A company allows engineers to access a production management portal from the Internet. During a security assessment, you discover that several contractor accounts are still active after their projects ended, and some of those accounts can log in outside business hours from unmanaged devices. Management wants a control that will reduce the attack surface immediately without redesigning the application. Which control is the MOST appropriate to implement first?

  1. A

    Apply role-based access control (RBAC) with a formal account review and deprovisioning process

  2. B

    Enable full-disk encryption on the production portal server

  3. C

    Deploy a honeypot that mirrors the production portal

  4. D

    Replace the portal's HTTPS certificate with one using a stronger hashing algorithm

Show answer and explanation

Correct answer: A

Explanation

The scenario points to a failure in access control management, specifically excessive permissions, orphaned accounts, and insufficient enforcement of least privilege. The most appropriate first control is to implement stronger logical access controls through RBAC, supported by formal joiner-mover-leaver procedures, periodic account reviews, and timely deprovisioning. This aligns with widely accepted best practices in access control and identity governance. NIST SP 800-53 emphasizes controls such as AC-2 (Account Management) and AC-3 (Access Enforcement), and the principle of least privilege is foundational across security frameworks. From a CEH perspective, understanding security controls means selecting the control that most directly reduces exploitable exposure. In this case, preventive access control is more effective than detective or unrelated technical hardening measures.

  • A. Correct.

    Correct. The primary issue is excessive and inappropriate access: former contractors still have valid accounts, and current accounts are being used under conditions that increase risk. RBAC, combined with periodic access reviews and prompt deprovisioning, is a preventive administrative and technical control that enforces least privilege and removes unnecessary access. This directly addresses the identified problem and reduces the attack surface quickly without requiring an application redesign.

  • B. Incorrect.

    Incorrect. Full-disk encryption protects data at rest on the server if the storage media is lost or stolen, but it does not address active misuse of valid accounts, access by former contractors, or logins from unmanaged devices. Someone might choose this because encryption is an important security control, but it is not the most relevant first step for the access-control problem described.

  • C. Incorrect.

    Incorrect. A honeypot can help detect or study malicious behavior, making it primarily a detective/deception control. However, it does not prevent unauthorized use of legitimate accounts on the real portal. This is a plausible distractor because honeypots can add visibility, but they do not solve the immediate access governance issue.

  • D. Incorrect.

    Incorrect. Strengthening the certificate or hashing algorithm may improve aspects of transport security and trust, but it does not mitigate the core risk of overprivileged or stale user accounts. A candidate might pick this if focusing on Internet exposure, but the scenario is clearly about identity and access management rather than weak cryptography.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam