CRISC Information Technology and Security Practice Question
A risk analyst is reviewing the organization's identity and access management (IAM) processes after a recent audit finding. The finding states that terminated employees retained active directory accounts for up to 30 days. Which control should the analyst recommend to BEST address this risk?
⚠ Common exam trap
The trap here is choosing a manual or detective control, such as a help desk ticket or quarterly review, when the finding demands immediate, automated revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement automated deprovisioning integrated with the HR system to disable accounts immediately upon termination.
The audit finding highlights a delay between termination and account disablement, creating a window for unauthorized access. An automated deprovisioning process integrated with the HR system is the most effective preventive control because it removes human latency and ensures accounts are disabled immediately upon termination. Manual tickets and periodic reviews are detective or delayed, and password expiration does not deactivate accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require managers to submit a ticket to the IT help desk within 24 hours of an employee's termination.
Why it's wrong here
A manual ticket process relies on manager diligence and help desk responsiveness, which can still introduce delays and human error. The audit finding showed accounts remained active for up to 30 days, indicating that manual processes are unreliable. While 24 hours is better than 30 days, it does not eliminate the risk of unauthorized access during the gap and is not as effective as automation.
- ✗
Enforce mandatory password changes every 30 days for all employees, including terminated ones.
Why it's wrong here
Password expiration does not disable an account; a terminated employee could still authenticate with a new password if they retain access to email or other recovery methods. This control also burdens active employees and does not address the root cause. The audit finding is about active accounts, not password age, so this recommendation fails to mitigate the risk of unauthorized access.
- ✗
Conduct quarterly access reviews to identify and disable accounts of terminated employees.
Why it's wrong here
Quarterly reviews are detective and occur too infrequently to prevent unauthorized access. A terminated employee could retain access for up to three months, far exceeding the 30-day finding. Access reviews are valuable for privilege creep, but they are not a timely control for termination. The risk requires immediate or near-immediate revocation, which reviews cannot provide.
- ✓
Implement automated deprovisioning integrated with the HR system to disable accounts immediately upon termination.
Why this is correct
Automated deprovisioning tied to the HR system ensures that account disablement occurs as soon as a termination is recorded, eliminating the 30-day window. This directly addresses the audit finding by reducing the risk of unauthorized access by former employees. It is a preventive control that is both efficient and auditable, and it aligns with least privilege and timely access revocation principles.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.