CISSP Identity and Access Management Practice Question
A security administrator is reviewing potential risks associated with orphaned accounts. Which TWO of the following are risks of orphaned accounts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attackers can use orphaned accounts to gain unauthorized access
Orphaned accounts are active accounts of former employees or unused accounts, which can be exploited to gain unauthorized access or persist undetected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compliance with password policies is weakened
Why it's wrong here
While password policies are typically still enforced on orphaned accounts, meaning they might still require complex passwords or periodic changes, the fundamental risk is the account's continued existence without a legitimate owner. The issue isn't a weakening of the policy's application, but rather the failure to adhere to the broader security policy requiring timely deprovisioning of accounts for departed users or unused services. The account itself, regardless of its password strength, represents an attack surface that should have been eliminated.
- ✗
Performance degradation of authentication servers
Why it's wrong here
Performance degradation of authentication servers due to orphaned accounts is generally minimal and not a primary concern. Unless an orphaned account is actively being brute-forced or exploited, it does not generate significant authentication requests or processing load. The overhead associated with a few inactive accounts residing in a directory service is negligible compared to the operational demands of legitimate user authentications or other directory operations.
- ✗
Increased logging overhead
Why it's wrong here
Increased logging overhead is not a primary risk directly attributable to the mere existence of orphaned accounts. While any activity, including failed login attempts on an orphaned account, would generate log entries, these accounts do not inherently produce more log data than active accounts unless they are being targeted for exploitation. The critical risk is the potential for unauthorized access or misuse, not the volume of log data generated by inactive or dormant entries.
- ✓
Attackers can use orphaned accounts to gain unauthorized access
Why this is correct
Attackers actively seek out orphaned accounts because they often represent overlooked security gaps. These accounts may retain elevated privileges, possess weak or default passwords that were never updated, or simply go unnoticed in routine security audits, making them prime targets for credential stuffing, brute-force attacks, or lateral movement once initial network access is achieved. Exploiting such accounts provides a persistent backdoor for unauthorized access and privilege escalation.
- ✓
Former employees can still access systems
Why this is correct
Former employees retaining access to systems via orphaned accounts poses a significant insider threat, whether intentional or accidental. If an account belonging to a departed staff member is not properly deprovisioned, that individual could still log in using their old credentials, potentially accessing sensitive data, intellectual property, or critical systems. This oversight can lead to data breaches, system sabotage, or compliance violations, leveraging the trust previously granted to their legitimate role.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.