WGU C845 VUN1 Task 1 | Passed on First Attem ny ny ny ny ny ny ny ny nyny
pt |Latest Update with Complete Solution
ny ny ny ny ny
VUN1 — ny
VUN1 Task 1: Managing Security Operations and Access Controls Information
ny ny ny ny ny ny ny ny ny ny ny
Systems Security - C845 ny ny ny
A. Apply an Access Control Model ny ny ny ny
A.1. Chosen Access Control Model ny ny ny
I have chosen the Role-Based Access Control (RBAC) model. The principles of RBAC are:
ny ny ny ny ny ny ny ny ny ny ny ny ny
• Role Assignment: A user is assigned to a role based on their job function (e.g., "Finan
ny ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ce Analyst").
ny
• Permission Assignment: Permissions to perform operations on systems are assigned to rol
ny ny ny ny ny ny ny ny ny ny ny
es, not to individual users.
ny ny ny ny
• Session Management: A user activates a role to gain the associated permissions for a session.
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
• Least Privilege: Users should only have the minimum level of access necessary to perform th
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
eir job duties.
ny ny
The organization's access control structure, as seen in the user matrix, is implicitly role-
ny ny ny ny ny ny ny ny ny ny ny ny ny
based (e.g., "Finance manager," "HR coordinator"). Applying a formal RBAC model would streamline t
ny ny ny ny ny ny ny ny ny ny ny ny ny
his by ensuring permissions are strictly tied to business functions, reducing complexity and the pot
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ential for user error when assigning permissions.
ny ny ny ny ny ny
A.2. Four Misalignments with RBAC Principles ny ny ny ny
1. Misalignment 1: Privilege Escalation Beyond Role Scope ny ny ny ny ny ny
• Description: The "Junior system admin" (J. Lopez) has "Domain admin" privileges. ny ny ny ny ny ny ny ny ny ny n
A junior role should not have the highest level of access in a Windows environ
y ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ment.
• Conflict with RBAC: This violates the principle of least privilege. The role "Junior syst
ny ny ny ny ny ny ny ny ny ny ny ny ny
em admin" implies a subset of administrative duties, not unrestricted domain-
ny ny ny ny ny ny ny ny ny ny
wide control. ny
2. Misalignment 2: Unnecessary Access Across Departments ny ny ny ny ny
messages.downloaded_by
,• Description: The "Finance analyst" (L. Cheng) has "Full access" to the CRM, a system
ny ny ny ny ny ny ny ny ny ny ny ny ny
messages.downloaded_by
, primarily for Sales and Support. A finance role typically does not require full modificati
ny ny ny ny ny ny ny ny ny ny ny ny ny
on rights in a customer relationship system.
ny ny ny ny ny ny
• Conflict with RBAC: This violates least privilege and separation of duties. It allows
ny ny ny ny ny ny ny ny ny ny ny ny ny
for potential data manipulation outside the user's core business function.
ny ny ny ny ny ny ny ny ny
3. Misalignment 3: Violation of User-Role Assignment Post-Termination
ny ny ny ny ny ny
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-
ny ny ny ny ny ny ny ny ny ny
20, has an "Active" account status and successfully logged in on 2025-06-29.
ny ny ny ny ny ny ny ny ny ny ny
• Conflict with RBAC: RBAC requires timely revocation of role assignments upon a chan
ny ny ny ny ny ny ny ny ny ny ny ny
ge in employment status. An active session for a terminated user completely bypass
ny ny ny ny ny ny ny ny ny ny ny ny
es the security provided by the role structure.
ny ny ny ny ny ny ny
4. Misalignment 4: Overly Broad Privileged Access
ny ny ny ny ny
• Description: The "IT administrator" (T. Miller) has "Full admin" access to "All inter
ny ny ny ny ny ny ny ny ny ny ny ny
nal systems," and the log shows they made a firewall rule change without a tic
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ket_id.
• Conflict with RBAC: While some access is necessary, blanket "Full admin" access
ny ny ny ny ny ny ny ny ny ny ny
violates least privilege and impedes accountability. It does not segment duties within t
ny ny ny ny ny ny ny ny ny ny ny ny
he IT department itself.
ny ny ny
messages.downloaded_by
pt |Latest Update with Complete Solution
ny ny ny ny ny
VUN1 — ny
VUN1 Task 1: Managing Security Operations and Access Controls Information
ny ny ny ny ny ny ny ny ny ny ny
Systems Security - C845 ny ny ny
A. Apply an Access Control Model ny ny ny ny
A.1. Chosen Access Control Model ny ny ny
I have chosen the Role-Based Access Control (RBAC) model. The principles of RBAC are:
ny ny ny ny ny ny ny ny ny ny ny ny ny
• Role Assignment: A user is assigned to a role based on their job function (e.g., "Finan
ny ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ce Analyst").
ny
• Permission Assignment: Permissions to perform operations on systems are assigned to rol
ny ny ny ny ny ny ny ny ny ny ny
es, not to individual users.
ny ny ny ny
• Session Management: A user activates a role to gain the associated permissions for a session.
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
• Least Privilege: Users should only have the minimum level of access necessary to perform th
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
eir job duties.
ny ny
The organization's access control structure, as seen in the user matrix, is implicitly role-
ny ny ny ny ny ny ny ny ny ny ny ny ny
based (e.g., "Finance manager," "HR coordinator"). Applying a formal RBAC model would streamline t
ny ny ny ny ny ny ny ny ny ny ny ny ny
his by ensuring permissions are strictly tied to business functions, reducing complexity and the pot
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ential for user error when assigning permissions.
ny ny ny ny ny ny
A.2. Four Misalignments with RBAC Principles ny ny ny ny
1. Misalignment 1: Privilege Escalation Beyond Role Scope ny ny ny ny ny ny
• Description: The "Junior system admin" (J. Lopez) has "Domain admin" privileges. ny ny ny ny ny ny ny ny ny ny n
A junior role should not have the highest level of access in a Windows environ
y ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ment.
• Conflict with RBAC: This violates the principle of least privilege. The role "Junior syst
ny ny ny ny ny ny ny ny ny ny ny ny ny
em admin" implies a subset of administrative duties, not unrestricted domain-
ny ny ny ny ny ny ny ny ny ny
wide control. ny
2. Misalignment 2: Unnecessary Access Across Departments ny ny ny ny ny
messages.downloaded_by
,• Description: The "Finance analyst" (L. Cheng) has "Full access" to the CRM, a system
ny ny ny ny ny ny ny ny ny ny ny ny ny
messages.downloaded_by
, primarily for Sales and Support. A finance role typically does not require full modificati
ny ny ny ny ny ny ny ny ny ny ny ny ny
on rights in a customer relationship system.
ny ny ny ny ny ny
• Conflict with RBAC: This violates least privilege and separation of duties. It allows
ny ny ny ny ny ny ny ny ny ny ny ny ny
for potential data manipulation outside the user's core business function.
ny ny ny ny ny ny ny ny ny
3. Misalignment 3: Violation of User-Role Assignment Post-Termination
ny ny ny ny ny ny
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-
ny ny ny ny ny ny ny ny ny ny
20, has an "Active" account status and successfully logged in on 2025-06-29.
ny ny ny ny ny ny ny ny ny ny ny
• Conflict with RBAC: RBAC requires timely revocation of role assignments upon a chan
ny ny ny ny ny ny ny ny ny ny ny ny
ge in employment status. An active session for a terminated user completely bypass
ny ny ny ny ny ny ny ny ny ny ny ny
es the security provided by the role structure.
ny ny ny ny ny ny ny
4. Misalignment 4: Overly Broad Privileged Access
ny ny ny ny ny
• Description: The "IT administrator" (T. Miller) has "Full admin" access to "All inter
ny ny ny ny ny ny ny ny ny ny ny ny
nal systems," and the log shows they made a firewall rule change without a tic
ny ny ny ny ny ny ny ny ny ny ny ny ny ny
ket_id.
• Conflict with RBAC: While some access is necessary, blanket "Full admin" access
ny ny ny ny ny ny ny ny ny ny ny
violates least privilege and impedes accountability. It does not segment duties within t
ny ny ny ny ny ny ny ny ny ny ny ny
he IT department itself.
ny ny ny
messages.downloaded_by