Courseiva

SY0-701 General Security Concepts Practice Question

A security analyst is evaluating the organization's identity and access management (IAM) practices. The company uses a federated identity system where employees authenticate with their corporate credentials to access a third-party SaaS application. The analyst wants to ensure that when an employee leaves the company, their access to the SaaS application is immediately revoked. Which of the following should the analyst verify is properly configured?

⚠ Common exam trap

The trap here is assuming that federated authentication alone handles de-provisioning, when in fact a separate provisioning protocol like SCIM is needed for lifecycle management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System for Cross-domain Identity Management (SCIM) provisioning

The key requirement is immediate revocation of access to a third-party SaaS application when an employee leaves. This is achieved through automated identity lifecycle management, specifically SCIM provisioning, which synchronizes user accounts between the identity provider and the SaaS app. SAML signing, OAuth scopes, and MFA address authentication and authorization but do not automate de-provisioning. SCIM ensures that when the user is disabled in the identity provider, the SaaS account is also disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    System for Cross-domain Identity Management (SCIM) provisioning

    Why this is correct

    SCIM is a standard for automating the exchange of user identity information between identity domains, such as an identity provider and a SaaS application. When properly configured, SCIM automatically provisions and de-provisions user accounts. If an employee leaves, the identity provider can send a SCIM request to deactivate the account in the SaaS app immediately, ensuring access is revoked without manual intervention.

  • ✗

    Multi-factor authentication (MFA) enforcement

    Why it's wrong here

    MFA adds an extra layer of security during authentication, but it does not revoke access when an employee leaves. Even with MFA, the user account remains active unless explicitly disabled. MFA is about verifying identity at login, not about lifecycle management. The scenario requires immediate revocation, which is achieved through automated provisioning/deprovisioning, not MFA.

  • ✗

    OAuth 2.0 scopes

    Why it's wrong here

    OAuth 2.0 scopes define the level of access granted to an application, such as read or write permissions. They do not manage user lifecycle. When an employee leaves, their access is revoked through the identity provider, not by changing OAuth scopes. Scopes are about authorization granularity, not about automatically removing access for departed users.

  • ✗

    Security Assertion Markup Language (SAML) assertion signing

    Why it's wrong here

    SAML assertion signing ensures the integrity and authenticity of the authentication assertions sent from the identity provider to the service provider. While important for security, it does not directly control user provisioning or de-provisioning. The revocation of access upon employee departure is handled by the identity lifecycle management, not by the signing of SAML assertions.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.