1. An IT company grants system administrators elevated permissions to manage critical servers and network configurations. These administrators use unique, secure credentials and multi-factor authentication to access sensitive systems, ensuring that only qualified personnel can perform high-risk tasks.
Select a match:
Answer: Privileged Access
2. A payroll administrator at a financial services company is responsible for processing employee salaries. Due to staffing shortages, they are also given approval access for salary disbursements, meaning they can both enter and approve payroll transactions.
Select a match:
Answer: Separation of Duties (SOD)
3. A customer support agent in a healthcare company accesses a patient's full medical history and Social Security number to verify their identity for a simple billing inquiry.
Select a match:
Answer: Personally Identifiable Information (PII)
The first scenario represents Privileged Access because system administrators hold elevated permissions that allow them to perform sensitive, high-impact operations on critical infrastructure. SailPoint identifies privileged entitlements as access that can expose sensitive data or create elevated security risk, making stronger controls such as MFA and dedicated credentials appropriate.
The second scenario represents Separation of Duties (SOD) . Allowing the same payroll administrator both to enter payroll transactions and approve salary disbursements creates conflicting responsibilities. SailPoint's SoD model specifically exists to prevent one identity from possessing combinations of access that allow them to initiate and independently authorize sensitive business transactions.
The third scenario involves Personally Identifiable Information (PII) because medical information combined with a Social Security number directly exposes sensitive information associated with an identifiable individual.
Study Guide Reference: Supporting Governance — Separation of Duties, Privileged Access, Sensitive Data and Identity Governance Controls.