Certified Ethical Hacker – CEH – 312-50 – Question331

The security concept of "separation of duties" is most similar to the operation of which type of security device?


A.
Firewall
B. Bastion host
C. Intrusion Detection System
D. Honeypot

Correct Answer: A

Explanation:

In most enterprises the engineer making a firewall change is also the one reviewing the firewall metrics for unauthorized changes. What if the firewall administrator wanted to hide something? How would anyone ever find out? This is where the separation of duties comes in to focus on the responsibilities of tasks within security.

References: http://searchsecurity.techtarget.com/tip/Modern-security-management-strategy-requires-security-separation-of-duties