Question 1 of 30
In a corporate environment, the IT security team is tasked with reviewing the access permissions of all employees to ensure compliance with the principle of least privilege. They discover that a group of employees in the marketing department has been granted access to sensitive financial data that they do not require for their job functions. What is the most appropriate action the IT security team should take to address this issue while adhering to best practices in identity and access management?
Revoke the unnecessary access permissions immediately and document the changes made.
Notify the marketing department about the access permissions and allow them to justify their need for access.
Conduct a full audit of all access permissions across the organization before making any changes.
Implement a temporary suspension of access to the financial data while further investigations are conducted.

Preparing for Microsoft SC-300 Microsoft Identity and Access Administrator? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free