Courseiva
Identity and Access ManagementmediumMultiple SelectObjective-mapped

CISSP Identity and Access Management Practice Question

A security administrator is reviewing potential risks associated with orphaned accounts. Which TWO of the following are risks of orphaned accounts?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attackers can use orphaned accounts to gain unauthorized access

Orphaned accounts are active accounts of former employees or unused accounts, which can be exploited to gain unauthorized access or persist undetected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Compliance with password policies is weakened

    Why it's wrong here

    While password policies are typically still enforced on orphaned accounts, meaning they might still require complex passwords or periodic changes, the fundamental risk is the account's continued existence without a legitimate owner. The issue isn't a weakening of the policy's application, but rather the failure to adhere to the broader security policy requiring timely deprovisioning of accounts for departed users or unused services. The account itself, regardless of its password strength, represents an attack surface that should have been eliminated.

  • Performance degradation of authentication servers

    Why it's wrong here

    Performance degradation of authentication servers due to orphaned accounts is generally minimal and not a primary concern. Unless an orphaned account is actively being brute-forced or exploited, it does not generate significant authentication requests or processing load. The overhead associated with a few inactive accounts residing in a directory service is negligible compared to the operational demands of legitimate user authentications or other directory operations.

  • Increased logging overhead

    Why it's wrong here

    Increased logging overhead is not a primary risk directly attributable to the mere existence of orphaned accounts. While any activity, including failed login attempts on an orphaned account, would generate log entries, these accounts do not inherently produce more log data than active accounts unless they are being targeted for exploitation. The critical risk is the potential for unauthorized access or misuse, not the volume of log data generated by inactive or dormant entries.

  • Attackers can use orphaned accounts to gain unauthorized access

    Why this is correct

    Attackers actively seek out orphaned accounts because they often represent overlooked security gaps. These accounts may retain elevated privileges, possess weak or default passwords that were never updated, or simply go unnoticed in routine security audits, making them prime targets for credential stuffing, brute-force attacks, or lateral movement once initial network access is achieved. Exploiting such accounts provides a persistent backdoor for unauthorized access and privilege escalation.

  • Former employees can still access systems

    Why this is correct

    Former employees retaining access to systems via orphaned accounts poses a significant insider threat, whether intentional or accidental. If an account belonging to a departed staff member is not properly deprovisioned, that individual could still log in using their old credentials, potentially accessing sensitive data, intellectual property, or critical systems. This oversight can lead to data breaches, system sabotage, or compliance violations, leveraging the trust previously granted to their legitimate role.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.