Courseiva
Identity and Access ManagementhardMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

An organization is implementing identity management and wants to ensure that when an employee leaves, all access is promptly revoked. Which process is most directly responsible for removing accounts and access rights for a leaver?

⚠ Common exam trap

Many candidates confuse 'Access Recertification' (a periodic review) with the immediate revocation action required for a leaver, or think 'Privileged Access Management' covers all account removal, when it only addresses high-privilege accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deprovisioning

Deprovisioning is the process of removing user accounts and access rights when an employee leaves the organization. It directly addresses the requirement to promptly revoke all access, ensuring that the former employee cannot authenticate or authorize any actions within the system. This process typically involves disabling or deleting the user object in the directory service (e.g., Active Directory) and removing associated permissions from all resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privileged access management

    Why it's wrong here

    Privileged Access Management (PAM) is a security discipline and set of technologies designed to secure, manage, and monitor access to critical assets and information. It specifically focuses on controlling elevated permissions for administrative accounts, service accounts, and other highly sensitive credentials, often involving session monitoring and just-in-time access. While PAM is crucial for securing a subset of identities, it does not encompass the broader identity lifecycle management process, such as the systematic removal of access for all departing employees. Therefore, it's not the primary mechanism for general user deprovisioning.

  • Access recertification

    Why it's wrong here

    Access recertification, also known as access review or attestation, is a periodic process where data owners or managers review and validate that existing user access rights remain appropriate and necessary for their roles. This process aims to identify and revoke stale or excessive permissions, ensuring the principle of least privilege is maintained over time. However, recertification is a scheduled audit and does not provide the immediate, event-driven mechanism required to revoke all access for an employee who has just departed the organization.

  • Deprovisioning

    Why this is correct

    Deprovisioning is the critical phase within the identity and access management (IAM) lifecycle that systematically revokes all access rights and disables or deletes user accounts when an individual's relationship with the organization ends or their role changes significantly. This process ensures that former employees or contractors can no longer access corporate resources, mitigating the risk of unauthorized access and data breaches. Effective deprovisioning involves removing access across all connected systems, applications, and physical access controls in a timely and comprehensive manner.

  • Separation of duties

    Why it's wrong here

    Separation of duties (SoD) is an internal control principle designed to prevent fraud, error, and abuse by ensuring that no single individual has complete control over a critical process or transaction. It mandates that different individuals perform distinct steps in a process, such as initiating, approving, and recording a financial transaction. While SoD is fundamental to designing secure processes, it is a control principle for assigning responsibilities, not an operational process for the immediate revocation of access rights when an employee leaves the organization.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.