組織のセキュリティ監査により、ほとんどの IT スタッフがドメイン管理者の資格情報を持っており、パスワードを定期的に変更していないことが判明しました。セキュリティ担当者は、調査結果を最も完全に解決するために、次のどのソリューションを提案する必要がありますか?
正解:D
Using a Privileged Access Management (PAM) vault to secure domain administrator credentials and enforcing role-based access control (RBAC) is the most comprehensive solution. PAM systems help manage and control access to privileged accounts, ensuring that only authorized personnel can access sensitive credentials. This approach also facilitates password rotation, auditing, and ensures that credentials are not misused or left unchanged. Integrating PAM with RBAC ensures that access is granted based on the user's role, further enhancing security. References = * CompTIA Security+ SY0-701 Course Content: Domain 05 Security Program Management and Oversight. * CompTIA Security+ SY0-601 Study Guide: Chapter on Identity and Access Management.