Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A multinational corporation has experienced…

A multinational corporation has experienced several security incidents where terminated employees retained access to internal systems for weeks after their departure. The HR department manually terminates accounts by sending notifications to IT, but the process is often delayed or missed. The company uses an identity management system (IDM) that supports automated provisioning and deprovisioning. The security team is tasked with reducing the risk of unauthorized access by former employees. Which of the following is the most effective course of action?

⚠ Common exam trap

A common mix-up: candidates choose 'increase access reviews' (Option C) because it sounds like a thorough security measure, but they fail to recognize that it is a detective control that does not prevent the immediate risk of unauthorized access by former employees.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Integrate the HR system with the identity management system for automated deprovisioning

Integrating the HR system with the identity management (IDM) system enables automated deprovisioning, ensuring that when an employee is terminated in HR records, the IDM immediately triggers account disablement across all connected systems. This eliminates the manual delay and human error inherent in the current notification-based process, directly addressing the root cause of the risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Integrate the HR system with the identity management system for automated deprovisioning

    Why this is correct

    Integrating the HR system with the identity management system establishes an authoritative source for employee status changes, enabling automated deprovisioning. This critical integration ensures that when an employee's status changes to terminated in HR, their accounts and access rights are immediately disabled across all connected systems. This proactive, system-driven approach minimizes the window of opportunity for unauthorized access post-termination, significantly reducing insider threat risks and enhancing compliance.

  • Require terminated employees to change their passwords upon exit

    Why it's wrong here

    Requiring terminated employees to change their passwords upon exit is an ineffective security measure because it does not revoke access or disable the account. While the old password becomes invalid, the account itself remains active, potentially with a new password known to the former employee or an accomplice. The fundamental vulnerability lies in the continued existence and activeness of the account, not merely the secrecy of the password, leaving systems exposed.

  • Increase frequency of access reviews and audits to identify stale accounts

    Why it's wrong here

    Increasing the frequency of access reviews and audits, while a valuable security practice, remains a reactive control for deprovisioning. There will inevitably be a time lag between an employee's termination and the next scheduled review cycle, during which the inactive account could be exploited. This method does not provide the immediate, real-time deactivation necessary to effectively mitigate the risk of unauthorized access by former employees.

  • Implement a user self-service portal for managers to disable accounts

    Why it's wrong here

    Implementing a user self-service portal for managers to disable accounts, while providing a tool, still relies on manual action and introduces significant human factors. This approach is susceptible to delays, oversights, or errors by managers, especially during busy periods or if communication about terminations is not immediate. It lacks the reliability, consistency, and immediacy of an automated, system-driven process, leaving a window for potential misuse.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.