SSCP Access Controls Practice Question
A financial institution uses a centralized authentication system. An auditor notes that when an employee is terminated, their access to several critical applications remains active for up to 24 hours because each application maintains its own local user database. Which of the following is the MOST effective control to reduce this window of exposure?
⚠ Common exam trap
The trap here is focusing on perimeter or policy controls instead of the identity lifecycle management that actually revokes access across multiple systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a centralized identity management system with automated provisioning and deprovisioning.
The core issue is that each application maintains its own user database, causing manual and delayed deprovisioning. A centralized identity management system with automated provisioning and deprovisioning solves this by integrating with applications and immediately disabling accounts upon termination. The other options do not address the root cause of decentralized, delayed account revocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require employees to sign a security awareness policy acknowledging immediate termination of access.
Why it's wrong here
A signed policy does not technically enforce timely deprovisioning. It may raise awareness but does not change the fact that each application maintains its own database and deactivation is manual and delayed. The exposure window remains because the policy does not automate or centralize account revocation.
- ✗
Implement a mandatory password change every 30 days for all users.
Why it's wrong here
Frequent password changes do not address the delay in revoking access across multiple applications. A terminated employee's credentials would still be valid until the next password change, and changing passwords does not disable accounts. This control is unrelated to the problem of decentralized account deactivation and does not reduce the 24-hour exposure window.
- ✗
Implement network access control (NAC) to restrict terminated employees' devices from connecting to the network.
Why it's wrong here
NAC can block devices from network access, but it does not revoke application-level accounts. A terminated employee could still access critical applications from an external network or via VPN if their credentials remain active. NAC addresses device connectivity, not the 24-hour account deactivation delay in application databases.
- ✓
Deploy a centralized identity management system with automated provisioning and deprovisioning.
Why this is correct
A centralized identity management system can automate the provisioning and deprovisioning of accounts across all connected applications. When an employee is terminated, the system can immediately disable or delete their accounts in all integrated systems, eliminating the 24-hour delay caused by separate local databases. This directly addresses the root cause of the exposure.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.