Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is reviewing the organization's account management procedures. The administrator discovers that user accounts for terminated employees remain active for up to 30 days after departure. Which account management control should the administrator implement to address this risk?

⚠ Common exam trap

The trap here is selecting a control that strengthens authentication or reviews access periodically, when the actual gap is the delay in disabling accounts after termination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement an automated account deprovisioning process tied to HR termination records

An automated deprovisioning process linked to HR termination records disables accounts immediately upon termination, eliminating the 30-day window of exposure. Manual or periodic controls cannot match this timeliness. This is the most direct and effective control for ensuring departed employees lose access promptly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enforce a password expiration policy of 30 days

    Why it's wrong here

    Password expiration forces users to change passwords periodically, but it does not disable accounts when employees leave. A terminated employee's account would remain active and usable with the current password until it expires. This control addresses credential aging, not the timely revocation of access for departed personnel.

  • ✓

    Implement an automated account deprovisioning process tied to HR termination records

    Why this is correct

    Automated deprovisioning triggered by HR termination records ensures accounts are disabled or removed as soon as the employment status changes. This directly reduces the window of unauthorized access and eliminates reliance on manual, error-prone processes. It addresses the root cause: accounts remaining active after termination.

  • ✗

    Conduct quarterly access reviews of all user accounts

    Why it's wrong here

    Quarterly access reviews can identify stale accounts, but they occur too infrequently to close a 30-day gap. A terminated employee could retain access for up to three months before the next review. Reviews are a detective control, whereas the scenario requires a preventive, timely deprovisioning mechanism.

  • ✗

    Require multi-factor authentication for all user accounts

    Why it's wrong here

    Multi-factor authentication strengthens authentication for active users, but a terminated employee who still possesses a valid credential and token could still authenticate. It does not remove or disable the account, so the orphaned account remains a risk. This control hardens access rather than revoking it.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.