WGU C845 VUN1 Task 1 | Passed on First Attem nc nc nc nc nc nc nc nc ncnc
pt |Latest Update with Complete Solution
nc nc nc nc nc
VUN1 — nc
VUN1 Task 1: Managing Security Operations and Access Controls Information S
nc nc nc nc nc nc nc nc nc nc nc
ystems Security - C845 nc nc nc
A. Apply an Access Control Model nc nc nc nc
A.1. Chosen Access Control Model nc nc nc
I have chosen the Role-Based Access Control (RBAC) model. The principles of RBAC are:
nc nc nc nc nc nc nc nc nc nc nc nc nc
• Role Assignment: A user is assigned to a role based on their job function (e.g., "Finan
nc nc nc nc nc nc nc nc nc nc nc nc nc nc nc
ce Analyst").
nc
• Permission Assignment: Permissions to perform operations on systems are assigned to role
nc nc nc nc nc nc nc nc nc nc nc
s, not to individual users.
nc nc nc nc
• Session Management: A user activates a role to gain the associated permissions for a session.
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
• Least Privilege: Users should only have the minimum level of access necessary to perform th
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
eir job duties.
nc nc
The organization's access control structure, as seen in the user matrix, is implicitly role-
nc nc nc nc nc nc nc nc nc nc nc nc nc
based (e.g., "Finance manager," "HR coordinator"). Applying a formal RBAC model would streamline t
nc nc nc nc nc nc nc nc nc nc nc nc nc
his by ensuring permissions are strictly tied to business functions, reducing complexity and the pote
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
ntial for user error when assigning permissions.
nc nc nc nc nc nc
A.2. Four Misalignments with RBAC Principles nc nc nc nc
1. Misalignment 1: Privilege Escalation Beyond Role Scope nc nc nc nc nc nc
• Description: The "Junior system admin" (J. Lopez) has "Domain admin" privileges. nc nc nc nc nc nc nc nc nc nc nc
A junior role should not have the highest level of access in a Windows environ
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
ment.
• Conflict with RBAC: This violates the principle of least privilege. The role "Junior syste
nc nc nc nc nc nc nc nc nc nc nc nc nc
m admin" implies a subset of administrative duties, not unrestricted domain-
nc nc nc nc nc nc nc nc nc nc
wide control. nc
2. Misalignment 2: Unnecessary Access Across Departments nc nc nc nc nc
messages.downloaded_by
,• Description: The "Finance analyst" (L. Cheng) has "Full access" to the CRM, a system
nc nc nc nc nc nc nc nc nc nc nc nc nc
messages.downloaded_by
, primarily for Sales and Support. A finance role typically does not require full modificati
nc nc nc nc nc nc nc nc nc nc nc nc nc
on rights in a customer relationship system.
nc nc nc nc nc nc
• Conflict with RBAC: This violates least privilege and separation of duties. It allows f
nc nc nc nc nc nc nc nc nc nc nc nc nc
or potential data manipulation outside the user's core business function.
nc nc nc nc nc nc nc nc nc
3. Misalignment 3: Violation of User-Role Assignment Post-Termination
nc nc nc nc nc nc
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-
nc nc nc nc nc nc nc nc nc nc
20, has an "Active" account status and successfully logged in on 2025-06-29.
nc nc nc nc nc nc nc nc nc nc nc
• Conflict with RBAC: RBAC requires timely revocation of role assignments upon a chan
nc nc nc nc nc nc nc nc nc nc nc nc
ge in employment status. An active session for a terminated user completely bypass
nc nc nc nc nc nc nc nc nc nc nc nc
es the security provided by the role structure.
nc nc nc nc nc nc nc
4. Misalignment 4: Overly Broad Privileged Access
nc nc nc nc nc
• Description: The "IT administrator" (T. Miller) has "Full admin" access to "All intern
nc nc nc nc nc nc nc nc nc nc nc nc
al systems," and the log shows they made a firewall rule change without a ticke
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
t_id.
• Conflict with RBAC: While some access is necessary, blanket "Full admin" access
nc nc nc nc nc nc nc nc nc nc nc
violates least privilege and impedes accountability. It does not segment duties within t
nc nc nc nc nc nc nc nc nc nc nc nc
he IT department itself.
nc nc nc
messages.downloaded_by
pt |Latest Update with Complete Solution
nc nc nc nc nc
VUN1 — nc
VUN1 Task 1: Managing Security Operations and Access Controls Information S
nc nc nc nc nc nc nc nc nc nc nc
ystems Security - C845 nc nc nc
A. Apply an Access Control Model nc nc nc nc
A.1. Chosen Access Control Model nc nc nc
I have chosen the Role-Based Access Control (RBAC) model. The principles of RBAC are:
nc nc nc nc nc nc nc nc nc nc nc nc nc
• Role Assignment: A user is assigned to a role based on their job function (e.g., "Finan
nc nc nc nc nc nc nc nc nc nc nc nc nc nc nc
ce Analyst").
nc
• Permission Assignment: Permissions to perform operations on systems are assigned to role
nc nc nc nc nc nc nc nc nc nc nc
s, not to individual users.
nc nc nc nc
• Session Management: A user activates a role to gain the associated permissions for a session.
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
• Least Privilege: Users should only have the minimum level of access necessary to perform th
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
eir job duties.
nc nc
The organization's access control structure, as seen in the user matrix, is implicitly role-
nc nc nc nc nc nc nc nc nc nc nc nc nc
based (e.g., "Finance manager," "HR coordinator"). Applying a formal RBAC model would streamline t
nc nc nc nc nc nc nc nc nc nc nc nc nc
his by ensuring permissions are strictly tied to business functions, reducing complexity and the pote
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
ntial for user error when assigning permissions.
nc nc nc nc nc nc
A.2. Four Misalignments with RBAC Principles nc nc nc nc
1. Misalignment 1: Privilege Escalation Beyond Role Scope nc nc nc nc nc nc
• Description: The "Junior system admin" (J. Lopez) has "Domain admin" privileges. nc nc nc nc nc nc nc nc nc nc nc
A junior role should not have the highest level of access in a Windows environ
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
ment.
• Conflict with RBAC: This violates the principle of least privilege. The role "Junior syste
nc nc nc nc nc nc nc nc nc nc nc nc nc
m admin" implies a subset of administrative duties, not unrestricted domain-
nc nc nc nc nc nc nc nc nc nc
wide control. nc
2. Misalignment 2: Unnecessary Access Across Departments nc nc nc nc nc
messages.downloaded_by
,• Description: The "Finance analyst" (L. Cheng) has "Full access" to the CRM, a system
nc nc nc nc nc nc nc nc nc nc nc nc nc
messages.downloaded_by
, primarily for Sales and Support. A finance role typically does not require full modificati
nc nc nc nc nc nc nc nc nc nc nc nc nc
on rights in a customer relationship system.
nc nc nc nc nc nc
• Conflict with RBAC: This violates least privilege and separation of duties. It allows f
nc nc nc nc nc nc nc nc nc nc nc nc nc
or potential data manipulation outside the user's core business function.
nc nc nc nc nc nc nc nc nc
3. Misalignment 3: Violation of User-Role Assignment Post-Termination
nc nc nc nc nc nc
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-
nc nc nc nc nc nc nc nc nc nc
20, has an "Active" account status and successfully logged in on 2025-06-29.
nc nc nc nc nc nc nc nc nc nc nc
• Conflict with RBAC: RBAC requires timely revocation of role assignments upon a chan
nc nc nc nc nc nc nc nc nc nc nc nc
ge in employment status. An active session for a terminated user completely bypass
nc nc nc nc nc nc nc nc nc nc nc nc
es the security provided by the role structure.
nc nc nc nc nc nc nc
4. Misalignment 4: Overly Broad Privileged Access
nc nc nc nc nc
• Description: The "IT administrator" (T. Miller) has "Full admin" access to "All intern
nc nc nc nc nc nc nc nc nc nc nc nc
al systems," and the log shows they made a firewall rule change without a ticke
nc nc nc nc nc nc nc nc nc nc nc nc nc nc
t_id.
• Conflict with RBAC: While some access is necessary, blanket "Full admin" access
nc nc nc nc nc nc nc nc nc nc nc
violates least privilege and impedes accountability. It does not segment duties within t
nc nc nc nc nc nc nc nc nc nc nc nc
he IT department itself.
nc nc nc
messages.downloaded_by