Your company has a human resources department, a finance department, a sales department, and an R&D department.
The company audits the access of documents that contain department-specific sensitive information.
You are planning an administrative model for the departments to meet the following requirements:
– Provide R&D managers with the ability to back up all the files of their department only.
– Provide finance managers with the ability to view the audit logs for the files of their department only.
– Provide human resources managers with the ability to view the audit logs for the files of their department only.
– Provide sales managers with the ability to modify the permissions on all the shared folders of their department only.
You need to identify the minimum amount of file servers required on the network to meet the requirements of each department.
How many file servers should you identify?
A.
1
B.
2
C.
3
D.
4
Explanation:
Finance managers & human resources (2 fileserver) need separate for sake of security (If we assign permission for both of them to view audit logs, then they will be
able to see ALL audit logs on the server – including that of the other department).
The R&D Managers will need their own file server too because backup operators can view and backup all files on the server.
Sales managers can use either one of he auditing departments fileservers… Finance managers & human resources each have their own file server for auditing, we
can simply throw the Sales managers onto one of those servers and delegate permissions for them (they obviously wont be able to view audit logs of the other
department on the server).
Certbase notes:
If we assume that the head of the Research and Development Department to use Windows Server Backup for backing up your data, the department must have its
own file server. Membership in the Administrators group or the Backup Operators group is required for using Windows Server Backup. Members of these groups
can create backups of all files. The departments accounting and personnel also require each have their own file server.
Here it is important to ensure that the head of department can only view audit records for the files of their own department. The request of the head of sales
department can be satisfied on fairly simple manner. The appropriate user accounts can get full access to their department folder and the permissions then
autonomously manage. To meet this requirement, a separate file server is required. Since no monitoring is required, the data can be provided on the file server of
the accounting or the file server of the HR department.
Good explanation in the description. To view one dept’s audit logs only, you need separate servers as audit logs are not separated by dept and are viewed as a whole.
1 server for both depts that just want to share/manage files
1 server for finance
1 server for HR