Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that a former employee's account can still access the company's cloud storage. Which security practice has been violated?

⚠ Common exam trap

Test-takers frequently confuse the symptom (the account still has access) with the principle of least privilege, but the question is about the failure to remove the account entirely, not about adjusting permission levels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Account management

Account management is the security practice of creating, modifying, and disabling user accounts as personnel change roles or leave the organization. When a former employee's account remains active and can still access cloud storage, the organization has failed to properly deprovision that account, violating account management procedures. This is a direct failure in the identity lifecycle process, not a failure of permission levels or data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege is a design principle that restricts users to the minimum permissions required for their current duties, but it addresses how much access a user has, not whether the user should still be a valid account at all. Even if this former employee's account had very limited rights, the account itself remains an active threat vector because it was never removed or disabled after termination. The security failure here is not excessive entitlements assigned to the account; it is the failure to initiate deprovisioning as part of the employee offboarding process.

  • ✓

    Account management

    Why this is correct

    Account management is the correct concept because it encompasses the entire identity lifecycle: provisioning accounts when employees join, reviewing access periodically, and deprovisioning accounts when employees leave. A former employee retaining network or application access indicates a breakdown in the account termination phase of account management. Effective account management requires a formal offboarding process that immediately disables or deletes accounts upon separation, revokes all associated tokens or certificates, and ensures any federated or local access is terminated.

  • ✗

    Data encryption

    Why it's wrong here

    Data encryption protects the confidentiality of data while it is stored or transmitted by rendering it unreadable without the proper decryption key. Encryption does not control whether a specific user account can be authenticated or authorized to access the storage container; it simply ensures that if unauthorized access occurs, the data cannot be understood. Since the former employee's account is still active, the system likely grants legitimate authenticated access, meaning encryption would not present a barrier. The issue is an access control failure, not a cryptographic failure.

  • ✗

    Role-based access control

    Why it's wrong here

    Role-based access control (RBAC) maps permissions to organizational roles rather than to individuals, and it helps manage the rights assigned to active accounts. A former employee's account may still be assigned its pre-departure role, but the violation isn't that the role is misconfigured or overly permissive; it's that the account should have been removed from the identity repository entirely. RBAC does not by itself enforce account expiry or termination workflows, so the lingering access stems from incomplete deprovisioning, not from a role-content error.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.