A company wants to protect its network using different levels of access control. User role Access level Justification Receptionist Can view customer contact...

Assessment: Computer Science (9-1) 0984 | Paper 1 Mock 01 | Computer Systems Subject: Computer Science (9-1) - 0984

Question 1 Report

A company wants to protect its network using different levels of access control.

User roleAccess levelJustification
ReceptionistCan view customer contact details only
Sales managerCan view and edit customer orders and contact details
IT administratorFull access to all systems and data
Temporary internRead-only access to training materials

(a) Complete the table by giving a justification for each user role's access level. [4]

(b) Explain two risks that could arise if all employees were given full access to all data. [4]

Answer Details

(a) Justification for each user role's access level [4]

User RoleAccess LevelJustification
ReceptionistCan view customer contact details onlyThe receptionist only needs contact details to direct enquiries and schedule appointments. They do not need access to financial records, order data, or other sensitive business information. [1]
Sales managerCan view and edit customer orders and contact detailsThe sales manager needs to view customer records to manage client accounts and must be able to edit orders to process new sales, handle returns, and respond to customer queries. [1]
IT administratorFull access to all systems and dataThe IT administrator requires full access to configure systems, install and update software, create and manage user accounts, and troubleshoot problems across the entire network infrastructure. [1]
Temporary internRead-only access to training materialsThe intern is only in the company for a short period and should have minimal access to reduce the risk of accidental data changes or security breaches. Read-only training materials are sufficient for their learning role. [1]

(b) Two risks if all employees were given full access [4]

  1. Employees could accidentally modify or delete critical data that they are not trained to handle (e.g. a receptionist accidentally editing a financial record), [1] potentially causing serious operational disruption or financial loss that may be difficult or impossible to reverse. [1]
  2. A disgruntled employee with full access could deliberately steal, alter, or destroy sensitive company data. [1] With all users having the same privileges, it would also be much harder to identify the source of a breach from audit logs, since everyone had equal access. [1]

Download The App On Google Playstore

Everything you need to excel in your exams

Green Bridge CBT Mobile App
Personalized AI Learning Chat Assistant
200,000+ Exam Questions Across IGCSE, JAMB, WAEC & NECO
Over 3,900 Lesson Notes
Offline Support - Learn Anytime, Anywhere
Green Bridge Timetable
Literature Summaries & Potential Questions
Track Your Performance & Progress
In-depth Explanations for Comprehensive Learning