Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A company is designing a new cloud application that will handle highly sensitive customer data. They want to ensure that every action taken by an administrator within the application is recorded, including who performed the action, what they did, and when. This is crucial for forensic investigations and compliance. Which identity concept is primarily focused on recording these actions?
- AAuthentication
- BAuditing
- CAuthorization
- DFederated Identity
Show answer & explanationAnswer & explanation
Correct answer: B. Auditing
Auditing (or accounting) is the process of recording and reviewing events and actions within a system to maintain a security log. The scenario explicitly describes the need for actions to be 'recorded, including who performed the action, what they did, and when', which is the definition of auditing.
Why the other options are wrong
- A. Authentication verifies identity, it does not record actions.
- C. Authorization grants permissions, it does not record actions taken.
- D. Federated Identity allows shared identity management across multiple organizations, which is unrelated to recording actions within a single application.
Auditing (Accounting)
The process of recording and reviewing events and actions within a security system to maintain a log of activity, crucial for accountability and forensic analysis.
- Tracks user actions and system events.
- Provides a trail for accountability and non-repudiation.
- Essential for compliance and security investigations.
Memory trick: Auditing Always Accounts for Actions.