When adding several development interns who need limited access for a summer, which provisioning technique should be used?

Enhance your skills for the CompTIA Cloud+ exam. Prepare with interactive quizzes, detailed explanations, and real exam simulations. Set the stage for your cloud certification success!

Multiple Choice

When adding several development interns who need limited access for a summer, which provisioning technique should be used?

Explanation:
Temporary access for a group of interns should be handled with identifiable identities and controlled permissions that end when the internship ends. The best approach is to create a role that contains only the permissions the interns need and grant each intern their own account that is a member of that role, with an expiration date set for the end of the summer. This setup supports the principle of least privilege, provides clear auditability because each intern has a unique identity, and makes revocation straightforward when the internship concludes. Other approaches compromise security and traceability. Sharing a single account prevents accurate auditing of actions and complicates revocation. Using a cloned or template account can blur accountability and may propagate permissions in unintended ways. And relying on a generic temporary group without individual accounts undermines traceability and access control.

Temporary access for a group of interns should be handled with identifiable identities and controlled permissions that end when the internship ends. The best approach is to create a role that contains only the permissions the interns need and grant each intern their own account that is a member of that role, with an expiration date set for the end of the summer. This setup supports the principle of least privilege, provides clear auditability because each intern has a unique identity, and makes revocation straightforward when the internship concludes.

Other approaches compromise security and traceability. Sharing a single account prevents accurate auditing of actions and complicates revocation. Using a cloned or template account can blur accountability and may propagate permissions in unintended ways. And relying on a generic temporary group without individual accounts undermines traceability and access control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy