ISC2 CC Security Principles Practice Question
A software development company wants to prevent a dismissed contractor from using credentials that were issued during the contract period to access internal code repositories. Which administrative control should the company apply?
⚠ Common exam trap
The trap here is treating a technical authentication hardening measure as a substitute for terminating a former worker's authorization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the contractor's access rights during offboarding
The scenario's core problem is that a former contractor retains valid credentials after the contract ends. Administrative controls govern people and processes, and timely revocation of access rights during offboarding removes the account's authority entirely. Monitoring detects but does not prevent, password complexity does not invalidate a known password, and MFA still lets the former contractor log in, so revocation is the correct control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy file integrity monitoring on the repositories
Why it's wrong here
File integrity monitoring detects unauthorized changes to files and can alert on suspicious activity, but it does not remove or disable a departed contractor's access. The contractor's credentials would still work, and the control would only report after the fact. The company needs to revoke access as part of the offboarding process, which is an administrative action, not a detective technical control.
- ✗
Enforce a password complexity policy for all accounts
Why it's wrong here
Password complexity makes credentials harder to guess or brute force, but the contractor already knows their own valid password. Complexity does nothing to stop a legitimate credential holder who should no longer have access. The issue is not credential strength but the continuing authorization of a former worker, so this control does not address the scenario's actual risk.
- ✗
Require multi-factor authentication for repository access
Why it's wrong here
Multi-factor authentication strengthens verification at login, but the dismissed contractor still possesses the enrolled factors and could continue to authenticate successfully. MFA reduces the risk of stolen or guessed credentials, not the risk of legitimate credentials held by someone whose authorization has ended. Access must be revoked rather than merely re-verified, so this control leaves the underlying problem in place.
- ✓
Revoke the contractor's access rights during offboarding
Why this is correct
Revoking access rights is the administrative control that directly removes the contractor's ability to authenticate and reach internal repositories once the engagement ends. Timely offboarding, including disabling accounts and removing group memberships, closes the window in which former credentials remain usable. This matches the scenario because the goal is to prevent a dismissed contractor from using issued credentials, which only revocation accomplishes.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Administrative control
An administrative control is a policy, procedure, or guideline designed to manage and reduce security risk through people and processes rather than technology alone.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.