WGUC845
WGU C845VUN1 Task1,2,&3| Passedon First Attempt|Latest
mm mm mm mm mm
Updatewith Complete Solution
mm mm mm
Testbankscove
, WGUC845VUN1Task1|PassedonFirst i
Attempt|LatestUpdatewithCompleteSolution
mm
VUN1—VUN1Task1:ManagingSecurityOperationsandAccessControls Information
i i mm
Systems Security - C845
mm mm mm mm
A. Applyan Access Control Model i mm mm
A.1. Chosen m m Access m m Control m m Model
Ihavechosenthe Role-Based Access Control(RBAC)model.The principles of RBACare:
mm mm mm mm mm mm
• RoleAssignment:Auserisassignedtoa rolebasedontheirjobfunction(e.g., "Finance i i
Analyst").
mm
• PermissionAssignment:Permissionsto performoperations onsystemsareassignedto roles, i i i
not to individual users.
mm mm mm mm
• Session Management: A useractivatesaroleto gainthe associatedpermissionsfor a session.
i mm mm mm mm mm mm
• LeastPrivilege:Usersshouldonlyhavetheminimumlevelofaccessnecessarytoperformtheir job mm
duties.
mm
The organization's access control structure, as seen in the user matrix, is implicitly role-
mm mm mm mm mm mm mm mm mm mm mm mm mm
based (e.g.,
mm
mm"Finance manager,""HR coordinator").Applyingaformal RBACmodelwouldstreamlinethisbyensuring
i i i
mmpermissions are strictly tied to business functions, reducing complexity and the potential
mm mm mm mm mm mm mm mm mm mm mm
for user error when assigning permissions.
mm mm mm mm mm mm
A.2. Four Misalignments m m m m with RBAC Principles
m m mm
1. Misalignment 1: Privilege Escalation Beyond Role Scope
mm mm mm mm mm mm
• Description:The"Juniorsystemadmin"(J.Lopez)has"Domainadmin"privileges.A
junior role should not have the highest level of access in a Windows
mm mm mm mm mm mm mm mm mm mm mm mm mm
environment. mm
• ConflictwithRBAC:This violates theprincipleof least privilege.Therole"Junior i mm mm i
system admin"impliesasubsetofadministrative duties,notunrestricteddomain-
mm mm i
widecontrol.
2. Misalignment2:Unnecessary Access AcrossDepartments mm mm
,• Description:The"Financeanalyst"(L.Cheng) has"Fullaccess"tothe CRM,asystem
mm mm
, primarily for Sales and Support. A finance role typically does not require full
mm mm mm mm mm mm mm mm mm mm mm mm
mmmodification rights in a customer relationship system.
mm mm mm mm mm mm
• Conflict with RBAC: This violates least privilege and separation of duties. It
mm mm mm mm mm mm mm mm mm mm mm
mmallows for potential data manipulation outside the user's core business
mm mm mm mm mm mm mm mm mm
mmfunction.
3. Misalignment3:Violation of User-RoleAssignment Post-Termination
mm mm mm
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-
mm mm mm mm mm mm mm mm mm mm
20, has an "Active" account status and successfully logged in on 2025-
mm mm mm mm mm mm mm mm mm mm mm
06-29.
• Conflictwith RBAC: RBACrequires timely
mm revocationofrole
mm assignments mm mm mm
mmuponachange in employment status. An active session for a terminated
mm mm mm mm mm mm mm mm mm
mmuser completely bypasses the security provided by the role structure.
mm mm m m mm mm mm mm mm mm
4. Misalignment4:OverlyBroadPrivilegedAccess
• Description: The "IT administrator" (T. Miller) has "Full admin" access to
mm mm mm mm mm mm mm mm mm mm
mm"All internal systems," and the log shows they made a firewall rule
mm mm mm mm mm mm mm mm mm mm mm
mmchange without a ticket_id.
mm mm mm
• ConflictwithRBAC:Whilesomeaccessis necessary,blanket"Fulladmin" access i m m
violates least privilege and impedes accountability. It does not segment duties
mm mm mm mm mm mm mm mm mm mm
mmwithin the IT department itself.
mm mm mm mm
WGU C845VUN1 Task1,2,&3| Passedon First Attempt|Latest
mm mm mm mm mm
Updatewith Complete Solution
mm mm mm
Testbankscove
, WGUC845VUN1Task1|PassedonFirst i
Attempt|LatestUpdatewithCompleteSolution
mm
VUN1—VUN1Task1:ManagingSecurityOperationsandAccessControls Information
i i mm
Systems Security - C845
mm mm mm mm
A. Applyan Access Control Model i mm mm
A.1. Chosen m m Access m m Control m m Model
Ihavechosenthe Role-Based Access Control(RBAC)model.The principles of RBACare:
mm mm mm mm mm mm
• RoleAssignment:Auserisassignedtoa rolebasedontheirjobfunction(e.g., "Finance i i
Analyst").
mm
• PermissionAssignment:Permissionsto performoperations onsystemsareassignedto roles, i i i
not to individual users.
mm mm mm mm
• Session Management: A useractivatesaroleto gainthe associatedpermissionsfor a session.
i mm mm mm mm mm mm
• LeastPrivilege:Usersshouldonlyhavetheminimumlevelofaccessnecessarytoperformtheir job mm
duties.
mm
The organization's access control structure, as seen in the user matrix, is implicitly role-
mm mm mm mm mm mm mm mm mm mm mm mm mm
based (e.g.,
mm
mm"Finance manager,""HR coordinator").Applyingaformal RBACmodelwouldstreamlinethisbyensuring
i i i
mmpermissions are strictly tied to business functions, reducing complexity and the potential
mm mm mm mm mm mm mm mm mm mm mm
for user error when assigning permissions.
mm mm mm mm mm mm
A.2. Four Misalignments m m m m with RBAC Principles
m m mm
1. Misalignment 1: Privilege Escalation Beyond Role Scope
mm mm mm mm mm mm
• Description:The"Juniorsystemadmin"(J.Lopez)has"Domainadmin"privileges.A
junior role should not have the highest level of access in a Windows
mm mm mm mm mm mm mm mm mm mm mm mm mm
environment. mm
• ConflictwithRBAC:This violates theprincipleof least privilege.Therole"Junior i mm mm i
system admin"impliesasubsetofadministrative duties,notunrestricteddomain-
mm mm i
widecontrol.
2. Misalignment2:Unnecessary Access AcrossDepartments mm mm
,• Description:The"Financeanalyst"(L.Cheng) has"Fullaccess"tothe CRM,asystem
mm mm
, primarily for Sales and Support. A finance role typically does not require full
mm mm mm mm mm mm mm mm mm mm mm mm
mmmodification rights in a customer relationship system.
mm mm mm mm mm mm
• Conflict with RBAC: This violates least privilege and separation of duties. It
mm mm mm mm mm mm mm mm mm mm mm
mmallows for potential data manipulation outside the user's core business
mm mm mm mm mm mm mm mm mm
mmfunction.
3. Misalignment3:Violation of User-RoleAssignment Post-Termination
mm mm mm
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-
mm mm mm mm mm mm mm mm mm mm
20, has an "Active" account status and successfully logged in on 2025-
mm mm mm mm mm mm mm mm mm mm mm
06-29.
• Conflictwith RBAC: RBACrequires timely
mm revocationofrole
mm assignments mm mm mm
mmuponachange in employment status. An active session for a terminated
mm mm mm mm mm mm mm mm mm
mmuser completely bypasses the security provided by the role structure.
mm mm m m mm mm mm mm mm mm
4. Misalignment4:OverlyBroadPrivilegedAccess
• Description: The "IT administrator" (T. Miller) has "Full admin" access to
mm mm mm mm mm mm mm mm mm mm
mm"All internal systems," and the log shows they made a firewall rule
mm mm mm mm mm mm mm mm mm mm mm
mmchange without a ticket_id.
mm mm mm
• ConflictwithRBAC:Whilesomeaccessis necessary,blanket"Fulladmin" access i m m
violates least privilege and impedes accountability. It does not segment duties
mm mm mm mm mm mm mm mm mm mm
mmwithin the IT department itself.
mm mm mm mm