easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A system administrator notices that user accounts…
A system administrator notices that user accounts are often left active after employees leave the company. Which process should be automated to address this?
⚠ Common exam trap
Test-takers frequently confuse authentication mechanisms (SSO, MFA, password policies) with identity lifecycle management, assuming any security control that involves accounts will solve the problem of orphaned accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated account provisioning and deprovisioning
Automated account provisioning and deprovisioning ensures that when an employee leaves the company, their access rights are automatically revoked in a timely manner. This process directly addresses the issue of orphaned accounts by integrating with HR systems to trigger account disablement or deletion upon termination, reducing the risk of unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Single sign-on implementation
Why it's wrong here
Single sign-on (SSO) implementation centralizes the authentication process, allowing users to access multiple applications with one set of credentials after a single login event. While SSO significantly improves user experience and can enhance security by reducing password fatigue, its primary function is identity federation and session management, not the automated creation or deactivation of user accounts based on employment status changes. Therefore, it does not directly address the problem of accounts remaining active for former employees.
- ✗
Password reset policy
Why it's wrong here
A password reset policy defines the rules and procedures for users to change or recover their forgotten or compromised passwords. This policy is a critical component of credential management and helps maintain account security for active users by ensuring strong, regularly updated passwords. However, a password reset policy is a reactive measure focused on individual user credentials and does not possess the functionality to identify, disable, or remove accounts belonging to former employees or those no longer requiring system access.
- ✗
Multi-factor authentication
Why it's wrong here
Multi-factor authentication (MFA) strengthens access security by requiring users to present two or more distinct verification factors (e.g., something you know, something you have, something you are) to prove their identity. While MFA significantly reduces the risk of unauthorized access, even if a password is stolen, it is an authentication mechanism that verifies a user's identity during login. MFA does not manage the lifecycle of user accounts, nor does it automatically identify or deactivate accounts that are no longer needed or associated with departed personnel.
- ✓
Automated account provisioning and deprovisioning
Why this is correct
Automated account provisioning and deprovisioning directly addresses the comprehensive lifecycle management of user identities across an organization's systems. This integrated process automatically creates accounts for new employees, modifies permissions as roles change, and critically, disables or deletes accounts promptly when an employee departs or no longer requires access. By synchronizing with authoritative sources like HR systems, it ensures that user accounts are always aligned with current employment status, significantly mitigating the security risk of orphaned or unauthorized active accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.