SY0-701 General Security Concepts Practice Question
A security analyst is evaluating the organization's identity and access management (IAM) practices. The company uses a federated identity system where employees authenticate with their corporate credentials to access a third-party SaaS application. The analyst wants to ensure that when an employee leaves the company, their access to the SaaS application is immediately revoked. Which of the following should the analyst verify is properly configured?
⚠ Common exam trap
The trap here is assuming that federated authentication alone handles de-provisioning, when in fact a separate provisioning protocol like SCIM is needed for lifecycle management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System for Cross-domain Identity Management (SCIM) provisioning
The key requirement is immediate revocation of access to a third-party SaaS application when an employee leaves. This is achieved through automated identity lifecycle management, specifically SCIM provisioning, which synchronizes user accounts between the identity provider and the SaaS app. SAML signing, OAuth scopes, and MFA address authentication and authorization but do not automate de-provisioning. SCIM ensures that when the user is disabled in the identity provider, the SaaS account is also disabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
System for Cross-domain Identity Management (SCIM) provisioning
Why this is correct
SCIM is a standard for automating the exchange of user identity information between identity domains, such as an identity provider and a SaaS application. When properly configured, SCIM automatically provisions and de-provisions user accounts. If an employee leaves, the identity provider can send a SCIM request to deactivate the account in the SaaS app immediately, ensuring access is revoked without manual intervention.
- ✗
Multi-factor authentication (MFA) enforcement
Why it's wrong here
MFA adds an extra layer of security during authentication, but it does not revoke access when an employee leaves. Even with MFA, the user account remains active unless explicitly disabled. MFA is about verifying identity at login, not about lifecycle management. The scenario requires immediate revocation, which is achieved through automated provisioning/deprovisioning, not MFA.
- ✗
OAuth 2.0 scopes
Why it's wrong here
OAuth 2.0 scopes define the level of access granted to an application, such as read or write permissions. They do not manage user lifecycle. When an employee leaves, their access is revoked through the identity provider, not by changing OAuth scopes. Scopes are about authorization granularity, not about automatically removing access for departed users.
- ✗
Security Assertion Markup Language (SAML) assertion signing
Why it's wrong here
SAML assertion signing ensures the integrity and authenticity of the authentication assertions sent from the identity provider to the service provider. While important for security, it does not directly control user provisioning or de-provisioning. The revocation of access upon employee departure is handled by the identity lifecycle management, not by the signing of SAML assertions.
Go deeper
Related to this question
Learn chapter
Cryptographic Key Management
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.