Certified Information Systems Security Professional – CISSP – Question342

An employee receives a promotion that entities them to access higher-level functions on the company’s accounting system, as well as keeping their access to the previous system that is no longer needed or applicable. What is the name of the process that tries to remove this excess privilege?

A.
Access provisioning
B. Segregation of Duties (SoD)
C. Access certification
D. Access aggregation

Correct Answer: B