Communication and Network Security Question #264

A company uses Kerberos for authentication across its internal systems. The security team is concerned about insider threats, specifically situations where users who are already authenticated might gain more access than their job role allows. Which Kerberos capability should be configured to control what an authenticated user is allowed to access, helping prevent privilege escalation?

A. Defining Service Principal Names (SPNs) for Kerberos-enabled services
B. Including authorization and role information inside Kerberos tickets
C. Enforcing Kerberos pre-authentication for all users
D. Requiring mutual authentication between clients and servers
Domain Concept: Communication and Network Security

This scenario evaluates management-level decision making in Communication and Network Security. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top