Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is reviewing the organization's account management process. The policy states that user accounts must be reviewed at least quarterly to ensure that only authorized individuals retain access. During an audit, it is discovered that several former employees still have active accounts. Which of the following is the MOST appropriate action to address this finding?

⚠ Common exam trap

The trap here is assuming that resetting passwords or deleting accounts is sufficient, when the primary goal is to revoke access quickly while preserving audit trails and addressing the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately disable the accounts and then review the account management process to identify why the accounts were not removed.

The most critical step is to immediately disable the accounts to eliminate the unauthorized access. Then, the administrator should investigate why the accounts were not removed to prevent similar issues. Deleting accounts can destroy evidence and is not best practice; resetting passwords does not revoke access; and delaying action increases risk. Thus, disabling and then reviewing the process is the correct approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Immediately disable the accounts and then review the account management process to identify why the accounts were not removed.

    Why this is correct

    Disabling the accounts immediately removes the unauthorized access risk posed by former employees. Following that, reviewing the process identifies the root cause of the failure to remove accounts, such as a missing trigger from HR, and allows the administrator to implement corrective controls to prevent recurrence. This aligns with the SSCP principle of least privilege and timely access revocation.

  • ✗

    Delete the accounts and then perform a full audit of all user accounts to ensure no other former employees have access.

    Why it's wrong here

    Deleting accounts may destroy audit trails and can cause issues if the account is needed for forensic purposes or if it is referenced by system processes. While auditing all accounts is good, the immediate action should be to disable rather than delete, and the root cause analysis is more important than just a one-time audit. Deletion is not the recommended first step.

  • ✗

    Document the finding in the audit report and schedule the account removals for the next quarterly review cycle.

    Why it's wrong here

    Delaying removal until the next quarterly review leaves the organization exposed to unauthorized access for an extended period. The finding indicates a failure of the existing process, so simply documenting and waiting does not mitigate the risk. Immediate action is required to disable the accounts and then fix the process to prevent future occurrences.

  • ✗

    Reset the passwords on the accounts and notify the former employees' managers to confirm whether access is still needed.

    Why it's wrong here

    Resetting passwords does not remove access; the former employees could still potentially regain access if they know the new password or if the reset is not properly communicated. Notifying managers is insufficient because the employees have already left. This approach does not address the immediate risk of unauthorized access and delays remediation.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.