Courseiva

GSEC Security Frameworks and CIS Controls Practice Question

A university is implementing CIS Control 6: Access Control Management. They want to ensure that user accounts are properly managed. Which of the following actions best aligns with the requirement to manage the lifecycle of user accounts?

⚠ Common exam trap

The trap here is focusing on authentication mechanisms like MFA or password policies, which are important but not the same as account lifecycle management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conducting quarterly reviews of all user accounts to identify and disable inactive accounts.

Quarterly reviews of user accounts directly support the lifecycle management requirement of CIS Control 6. By identifying and disabling inactive accounts, the university reduces the risk of unauthorized access through stale credentials. Other actions like password policies, MFA, and PAM are valuable but do not fulfill the specific need to manage account lifecycles across all users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conducting quarterly reviews of all user accounts to identify and disable inactive accounts.

    Why this is correct

    CIS Control 6 requires managing the lifecycle of user accounts, including periodic reviews to disable inactive accounts. Quarterly reviews help ensure that accounts are removed when no longer needed, reducing the attack surface. This action directly supports the control's intent.

  • ✗

    Implementing multi-factor authentication for all administrative access to servers.

    Why it's wrong here

    Multi-factor authentication is a critical control, often associated with CIS Control 6, but it focuses on authentication strength, not account lifecycle. The scenario specifically asks about managing the lifecycle, which includes creation, modification, and deletion of accounts.

  • ✗

    Deploying a privileged access management (PAM) solution to vault administrative credentials.

    Why it's wrong here

    PAM solutions help manage privileged accounts, which is part of CIS Control 5, but they do not cover the full lifecycle of all user accounts. The scenario is about general user account management, not just privileged accounts. PAM is a subset and does not address inactive standard accounts.

  • ✗

    Enforcing a password complexity policy that requires 12 characters with mixed case and symbols.

    Why it's wrong here

    Password complexity is part of CIS Control 5 (Administrative Privileges) or Control 4 (Secure Configuration), but it does not address the lifecycle management of accounts. While important, it does not ensure that accounts are disabled when users leave or become inactive.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.