Lab Objective

Completed Google Cybersecurity Certificate access-control worksheet: analyze a simulated payroll-change event, distinguish an account link from proof of attribution, identify IAM failures, and recommend layered controls.

Lab Environment

  • Course: Google Cybersecurity Certificate
  • Exercise type: completed scenario-based access-control worksheet
  • Evidence available: a payroll-change event, a directory record for a former contractor, and an authorization list
  • Safety boundary: this lab analyzes supplied training evidence only. No real account, payroll system, or organization was accessed.

Scenario

A payroll-related event was recorded under an administrative identity. The directory associated the source with a contractor whose assignment had ended years earlier. The worksheet also showed that broad administrative authorization had been granted to people who did not need payroll authority.

The task was not to accuse a named person. It was to identify what the evidence supports, what it does not support, and which controls would reduce the chance of a similar event.

Step 1 - Separate Observation From Attribution

I first recorded the evidence without turning it into a conclusion:

  • a sensitive payroll change was logged under an administrative identity
  • a directory record linked the source information to a former contractor
  • the contractor account had not been deprovisioned at the documented end of the assignment

The source-to-directory link is corroborating evidence. It does not prove who personally initiated the action. A compromised credential, shared access, or another attribution error remain possible until further evidence is reviewed.

Step 2 - Identify the Control Failures

The worksheet exposed two separate failures:

  1. Deprovisioning failure: an account remained active after the person’s contract ended.
  2. Least-privilege failure: broad administrative authorization was available to users and roles that did not need it.

These failures compound. A dormant account is already a risk; a dormant account with excessive authority has a much larger potential impact.

Step 3 - Build the Remediation Plan

I recommended controls across the IAM lifecycle:

  • enforce an offboarding workflow that disables accounts, revokes sessions, removes cloud access, and reviews dormant identities
  • replace broad default administration with role-based access control, giving payroll and beneficiary changes only to named finance roles
  • require individual identities and MFA for sensitive access
  • alert on former-user sign-ins, privileged actions, and payroll or bank-detail changes
  • require a second independent approver and verification step before sensitive payment changes

Step 4 - Define What to Monitor

Example detection hypothesis:

alert=former_user_account_active
source=identity_directory
condition=account_enabled_after_contract_end_date
risk=valid_account_with_unnecessary_access
response=disable_review_access_and_preserve_audit_evidence

Additional useful telemetry includes authentication logs, administrator-action logs, payroll-change records, and session-revocation evidence.

Security Takeaways

  1. An IP or directory association is a lead, not proof of a person’s action. Preserve attribution uncertainty until the evidence supports a conclusion.
  2. Offboarding is a security control. A contract end date must trigger technical removal of access, not just an HR record update.
  3. Least privilege limits blast radius. Broad administrative access converts an ordinary account failure into a high-impact financial risk.
  4. Separation of duties protects sensitive changes. One identity should not be able to create and release a payment change without independent review.
  5. Logs support accountability only when identities are individual and access is correctly scoped.

Where This Applies Beyond the Lab

The same method applies to cloud access, source-control administration, customer-data exports, and privileged infrastructure changes: separate what the log proves from what it merely suggests, remove access when the business relationship ends, and require stronger controls as the potential impact rises.