A security engineer at a large company needs to enhance IAM in order to ensure that employees can only access corporate systems during their shifts. Which of the following access controls should the security engineer implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Time-of-day restrictions.
Why this is the answer
Time-of-day restrictions are the most appropriate access control for this scenario because they directly address the requirement of limiting access to specific timeframes, such as an employee's shift. This control prevents unauthorized access outside of designated working hours, enhancing security. Role-based access control (RBAC) defines permissions based on job function but doesn't restrict access by time. Least privilege ensures users have only the necessary permissions but also doesn't inherently include time-based limitations. Biometric authentication verifies identity but doesn't control when that authenticated user can access systems.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed