220-1102 Security Practice Question
A user reports that a former employee's account can still access the company's cloud storage. Which security practice has been violated?
⚠ Common exam trap
Test-takers frequently confuse the symptom (the account still has access) with the principle of least privilege, but the question is about the failure to remove the account entirely, not about adjusting permission levels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Account management
Account management is the security practice of creating, modifying, and disabling user accounts as personnel change roles or leave the organization. When a former employee's account remains active and can still access cloud storage, the organization has failed to properly deprovision that account, violating account management procedures. This is a direct failure in the identity lifecycle process, not a failure of permission levels or data protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege is a design principle that restricts users to the minimum permissions required for their current duties, but it addresses how much access a user has, not whether the user should still be a valid account at all. Even if this former employee's account had very limited rights, the account itself remains an active threat vector because it was never removed or disabled after termination. The security failure here is not excessive entitlements assigned to the account; it is the failure to initiate deprovisioning as part of the employee offboarding process.
- ✓
Account management
Why this is correct
Account management is the correct concept because it encompasses the entire identity lifecycle: provisioning accounts when employees join, reviewing access periodically, and deprovisioning accounts when employees leave. A former employee retaining network or application access indicates a breakdown in the account termination phase of account management. Effective account management requires a formal offboarding process that immediately disables or deletes accounts upon separation, revokes all associated tokens or certificates, and ensures any federated or local access is terminated.
- ✗
Data encryption
Why it's wrong here
Data encryption protects the confidentiality of data while it is stored or transmitted by rendering it unreadable without the proper decryption key. Encryption does not control whether a specific user account can be authenticated or authorized to access the storage container; it simply ensures that if unauthorized access occurs, the data cannot be understood. Since the former employee's account is still active, the system likely grants legitimate authenticated access, meaning encryption would not present a barrier. The issue is an access control failure, not a cryptographic failure.
- ✗
Role-based access control
Why it's wrong here
Role-based access control (RBAC) maps permissions to organizational roles rather than to individuals, and it helps manage the rights assigned to active accounts. A former employee's account may still be assigned its pre-departure role, but the violation isn't that the role is misconfigured or overly permissive; it's that the account should have been removed from the identity repository entirely. RBAC does not by itself enforce account expiry or termination workflows, so the lingering access stems from incomplete deprovisioning, not from a role-content error.
Go deeper
Related to this question
Learn chapter
Software Patch Management
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Data protection
Data protection refers to the practices and technologies used to safeguard personal and sensitive information from unauthorized access, loss, or corruption.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.