An organization implements a role-based access control (RBAC…

An organization implements a role-based access control (RBAC) model. A penetration tester discovers that a user with the “intern” role can access HR data, which is supposed to be restricted to the “HR” role. Identify what likely went wrong in this RBAC setup. Propose a solution to fix this misconfiguration. Describe one additional safeguard that could prevent similar issues.