Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

WGU Managing Cloud Security (JY02) Exam - Topic 4 Question 10 Discussion

Actual exam question for WGU's WGU Managing Cloud Security (JY02) exam
Question #: 10
Topic #: 4
[All WGU Managing Cloud Security (JY02) Questions]

An accountant in an organization is allowed access to a company's human resources database only to adjust the number of hours that the organization's employees have worked in a fiscal year. However, the accountant modifies an employee's personal information. Which part of the STRIDE model describes this situation?

Show Suggested Answer Hide Answer
Suggested Answer: C

The STRIDE threat model identifies six categories: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege. In this scenario, the accountant modified data they were not authorized to change. This is an act of Tampering, which refers to unauthorized alteration of data or systems.

Spoofing would involve impersonating another identity, denial of service would block availability, and elevation of privilege would involve gaining higher access rights. The accountant already had legitimate access but misused it to alter data outside their scope of responsibility.

Tampering compromises data integrity, one of the pillars of the CIA triad. In cloud and enterprise systems, safeguards against tampering include role-based access control, least privilege, and auditing to detect unauthorized changes. Recognizing this as tampering helps in identifying insider misuse and implementing compensating controls.


Contribute your Thoughts:

0/2000 characters
Haley
17 days ago
This reminds me of a practice question where someone accessed data they shouldn't have. I feel like tampering fits here too.
upvoted 0 times
...
Stephen
22 days ago
I'm not entirely sure, but I remember something about elevation of privilege being related to gaining access to more than what you're allowed.
upvoted 0 times
...
Reita
27 days ago
I think this might be about tampering since the accountant changed personal information that they weren't authorized to modify.
upvoted 0 times
...

Save Cancel