220-1102 Security Practice Question
An annual security audit reveals that multiple user accounts belonging to former employees who left the company over a year ago are still active. This oversight could allow unauthorized access. Which process failure is most directly responsible for this security risk?
⚠ Common exam trap
A common mix-up: candidates confuse the onboarding process (which creates accounts) with the offboarding process (which removes them), leading them to select D, but the question specifically asks about the failure to remove accounts, which falls under account management policy, not onboarding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Account management policy
An account management policy defines the lifecycle of user accounts, including mandatory deactivation or deletion upon employee termination. The failure to disable accounts for former employees after more than a year indicates a breakdown in enforcing this policy, directly creating an unauthorized access risk. Without a proper account management policy, accounts remain active indefinitely, bypassing the principle of least privilege and exposing the network to potential credential misuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Account management policy
Why this is correct
Account management policy defines the full user identity lifecycle, including account creation, modification, privilege review, and timely deprovisioning. The audit finding that multiple accounts of former employees remain active is a direct violation of this policy, because it should require disabling access immediately upon termination. Failure to enforce this lifecycle control leaves orphaned credentials that can be used by unauthorized parties, making this the correct root-cause control.
- ✗
Incident response plan
Why it's wrong here
An incident response plan is a reactive framework for detecting, containing, eradicating, and recovering from active security events such as intrusions or malware outbreaks. It does not govern routine identity maintenance or the periodic cleanup of stale user accounts, so it would not have prevented the audit finding. The vulnerability exists due to missing lifecycle processes, not because of a lack of incident handling capabilities.
- ✗
Change management process
Why it's wrong here
Change management process governs modifications to IT infrastructure, such as hardware updates, software deployments, or configuration changes, ensuring they are authorized, tested, and documented. Disabling a departing user's account is an identity and access management action, not a change to enterprise infrastructure. While a change ticket might record the deactivation, the core deficiency is the absence of an account lifecycle procedure, so this option is not the correct control for the vulnerability.
- ✗
Onboarding process
Why it's wrong here
The onboarding process is designed to provision new employees with accounts, credentials, and appropriate access rights when they join the organization. The audit finding concerns accounts that should have been removed when employees left, which is the offboarding or deprovisioning phase of the identity lifecycle. Onboarding does not address termination procedures, so it cannot explain or remedy the continued existence of accounts belonging to former personnel.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.