An organization is implementing a new hybrid cloud deployment. Before granting access to any of the resources, the security team wants to ensure that all employees are checked against a database to see if any risk is posed to the organization by hiring them. Which type of security control is the organization leveraging for its employees?
Background check
A background check is a security control used to assess the potential risks posed by employees before granting them access to organizational resources. This process involves verifying an individual's history, which helps the organization ensure that hiring decisions do not compromise its security.
Authentication verifies the identity of a user attempting to access resources, typically through credentials like usernames and passwords. While essential for securing systems, it does not assess the background or trustworthiness of employees prior to their employment, making it an ineffective measure for pre-hire risk assessment.
A WAF is a security measure designed to protect web applications by filtering and monitoring HTTP traffic. Although it plays a crucial role in safeguarding applications from web-based attacks, it does not pertain to evaluating employee backgrounds or assessing hiring risks, thus making it unrelated to the scenario presented.
Authorization determines what resources an authenticated user can access and what actions they can perform. While important for controlling access levels based on user roles, it does not involve pre-employment checks or risk assessments of individuals, which is the focus of the security team's intention in this scenario.
In this context, the organization is utilizing a background check as a proactive security control to mitigate potential risks associated with new hires. This measure helps ensure that employees do not pose a threat to the organization's security before they are granted access to sensitive resources. In contrast, authentication, WAFs, and authorization operate on different aspects of security management and do not address the pre-employment risk assessment requirement.
Related Questions
View allAfter creating a backup set, an engineer stores the backups according...
Which methodology encompasses conducting tests around the interaction...
Which phase of the cloud data life cycle involves the process of crypt...
An engineer has been given the task of assuring all of the keys used t...
Which pillar encompasses the ability to support development and run wo...
Related Quizzes
View all0PC1 Planning Instructional Strategies for Meaningful Learning Version 1
AP01 Elementary Literacy Curriculum Version 1
AQ01 Applied Healthcare Statistics C784 Version 1
ASO1 Introduction to Statistics for Research Version 1
BJ01 Introduction to Business Finance Version 1
C172 Network and Security Foundations Version 1
C180 Introduction to Psychology Version 1
C180 Introduction to Psychology Version 2
CKC1 Introduction to Humanities Version 1
DZ01 Mathematics for Elementary Educators III MATH 1330 Version 1
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations