WGU C845 Task 1 |Passed on First Attempt |Latest Update with Complete
Solution
Managing Security Operations and Access Controls
A1. To ensure that access is consistent with business responsibilities and upholds the principle of least
privilege, Role-Based Access Control (RBAC) will align perfectly for this mid-size financial organization.
By implementing this Access Control Model for the organization, it will be easier to maintain least
privilege as well as Separation of Duties for future & current employees. (Authenication and Access to
Financial Instition Services and Systems)
A2. Upon initial inspection, I noticed that a newly hired individual, J. Lopez, Jr. System Administrator, held
Domain-Level administrative privileges. The use of RBAC ensures that only senior administrators who
have tasks that are more clearly defined are required to have access to this level. A violation of the
principle of least privilege has occurred, and the discrepancy has resulted in an increase in the
likelihood of a compromise that might have a negative effect on the entire system. J. Hall, a customer
support representative, has been able to read information inside of the payroll system. Payroll data is
not connected to the job duties of customer support, and RBAC mandates that permissions be strictly
linked with the responsibilities of the role. This access results in the exposure of sensitive financial
data because of unnecessary exposure. I also noticed that HR Assistant P. Ellis's role status has been
marked as terminated, the account continues to be active and provides access to both HR and payroll
systems. To avoid unauthorized access and the risk of sensitive information being compromised,
, RBAC mandates that access be revoked immediately upon termination without further delay. Lastly,
the "vendor_finapp" account has been given permission to access the finance application server as a
local administrator, which is fine but not for the entire duration of the contract, just the service
window. In accordance with RBAC, access given to vendors should be restricted, task-specific, and
time-bound. The duration of administrator-level access goes beyond the operational requirements of
the vendor and raises the level of risk, especially considering that information from User Matrix does
not define whether the account in question is, in fact, a temporary one.
A3. As the acting Security Analyst I would restrict Domain Admin Privileges to only Senior IT
Administrator, this would fix the Jr. System Admin issue and enforce least privilege. This would uphold
the NIST SP 800-53 framework as the Level of access is not necessary to accomplish organizational
tasks for the User. (Wilbur L. Ross, Jr., 2020) Payroll access should be restricted to Finance and HR
roles only, since these are the only personnel that have role that are aligned with business and
operational needs. (Holloway, 2025) Access should be revoked immediately upon termination or
contract expiration. (CIS Control 6: Access Control Management, 2025) NIST SP 800-53 AC-2 also
requires a timely removal of access to prevent unauthorized use, I would automate the revocation of
access of the accounts upon termination/contract end to ensure no time gaps are created.
A4. As part of the changes to the User Role Matrix, I would change the Jr. System Admin account from
Domain Admin access to Standard Admin access, which is a more limited level of access. Take away J.
Hall's access to payroll because customer support representatives don't need it for their jobs.
Disabling the account of the terminated HR Assistant and limiting vendor access to a more time-
limited focus and a non-admin role. Additionally, checking all access permissions to make sure they
are only used for the tasks that require them.
Assigned Employme Start End Role History (last Account Privilege
Role Dept. System Access
User nt Type Date Date change) Status Level
Finance 2018- Payroll system, budget
A. Jones Employee Finance — — Active Full access
manager 03-15 tracker
Promoted from
Finance 2020- Payroll system, budget
L. Cheng Employee Finance — finance intern Active Full access
analyst 07-02 tracker, CRM
(2021-06-01)
HR Lateral from HR
2021- Read and
coordinato M. Singh Employee HR — assistant (2023- Active HR portal, payroll system
01-12 write
r 02-10)
Security 2022- SIEM, network logs, firewall
K. Patel Employee SecOps — — Active Read only
analyst 04-10 console
Solution
Managing Security Operations and Access Controls
A1. To ensure that access is consistent with business responsibilities and upholds the principle of least
privilege, Role-Based Access Control (RBAC) will align perfectly for this mid-size financial organization.
By implementing this Access Control Model for the organization, it will be easier to maintain least
privilege as well as Separation of Duties for future & current employees. (Authenication and Access to
Financial Instition Services and Systems)
A2. Upon initial inspection, I noticed that a newly hired individual, J. Lopez, Jr. System Administrator, held
Domain-Level administrative privileges. The use of RBAC ensures that only senior administrators who
have tasks that are more clearly defined are required to have access to this level. A violation of the
principle of least privilege has occurred, and the discrepancy has resulted in an increase in the
likelihood of a compromise that might have a negative effect on the entire system. J. Hall, a customer
support representative, has been able to read information inside of the payroll system. Payroll data is
not connected to the job duties of customer support, and RBAC mandates that permissions be strictly
linked with the responsibilities of the role. This access results in the exposure of sensitive financial
data because of unnecessary exposure. I also noticed that HR Assistant P. Ellis's role status has been
marked as terminated, the account continues to be active and provides access to both HR and payroll
systems. To avoid unauthorized access and the risk of sensitive information being compromised,
, RBAC mandates that access be revoked immediately upon termination without further delay. Lastly,
the "vendor_finapp" account has been given permission to access the finance application server as a
local administrator, which is fine but not for the entire duration of the contract, just the service
window. In accordance with RBAC, access given to vendors should be restricted, task-specific, and
time-bound. The duration of administrator-level access goes beyond the operational requirements of
the vendor and raises the level of risk, especially considering that information from User Matrix does
not define whether the account in question is, in fact, a temporary one.
A3. As the acting Security Analyst I would restrict Domain Admin Privileges to only Senior IT
Administrator, this would fix the Jr. System Admin issue and enforce least privilege. This would uphold
the NIST SP 800-53 framework as the Level of access is not necessary to accomplish organizational
tasks for the User. (Wilbur L. Ross, Jr., 2020) Payroll access should be restricted to Finance and HR
roles only, since these are the only personnel that have role that are aligned with business and
operational needs. (Holloway, 2025) Access should be revoked immediately upon termination or
contract expiration. (CIS Control 6: Access Control Management, 2025) NIST SP 800-53 AC-2 also
requires a timely removal of access to prevent unauthorized use, I would automate the revocation of
access of the accounts upon termination/contract end to ensure no time gaps are created.
A4. As part of the changes to the User Role Matrix, I would change the Jr. System Admin account from
Domain Admin access to Standard Admin access, which is a more limited level of access. Take away J.
Hall's access to payroll because customer support representatives don't need it for their jobs.
Disabling the account of the terminated HR Assistant and limiting vendor access to a more time-
limited focus and a non-admin role. Additionally, checking all access permissions to make sure they
are only used for the tasks that require them.
Assigned Employme Start End Role History (last Account Privilege
Role Dept. System Access
User nt Type Date Date change) Status Level
Finance 2018- Payroll system, budget
A. Jones Employee Finance — — Active Full access
manager 03-15 tracker
Promoted from
Finance 2020- Payroll system, budget
L. Cheng Employee Finance — finance intern Active Full access
analyst 07-02 tracker, CRM
(2021-06-01)
HR Lateral from HR
2021- Read and
coordinato M. Singh Employee HR — assistant (2023- Active HR portal, payroll system
01-12 write
r 02-10)
Security 2022- SIEM, network logs, firewall
K. Patel Employee SecOps — — Active Read only
analyst 04-10 console