A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?
When an employee leaves, all access rights should be revoked as part of offboarding. Disabling the account is not sufficient if permissions remain on resources, because the account could be re-enabled or the permissions could be inherited by another account. The scenario shows that read and write permissions persisted, so the offboarding process failed to remove access properly.
Why this answer
Offboarding should include disabling the account and removing or transferring all associated permissions. The scenario shows that the account was disabled but its read and write permissions on the file server remained, indicating that access revocation was incomplete. Least privilege, separation of duties, and account recertification are valuable controls, but they do not directly describe the failure to strip permissions when the employee departed.
Exam trap
The trap here is assuming that disabling an account automatically removes its permissions, when in fact permissions often persist and must be explicitly revoked.