ISC2 CISSP Practice Question

A security administrator at a hospital is establishing access controls for the patient records system. Which of the following approaches BEST implements security best practices for minimizing unnecessary access?

  • Implementing function-specific permissions that restrict each user to accessing patient records required for their job responsibilities

  • Providing physicians access to patient records relevant to their cases in the hospital to ensure continuity of care

  • Implementing mandatory access controls based on security clearance levels for hospital staff

  • Requiring multi-factor authentication for users accessing the electronic health records system based on their access level

ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot