Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator needs to ensure that a terminated employee loses access to all systems immediately upon departure. Which action best accomplishes this?

⚠ Common exam trap

The trap here is believing that changing a password or removing payroll access terminates system access, when active sessions and directory identities remain valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the user account in the central directory and revoke active sessions and tokens.

Immediate access removal requires disabling the identity in the central directory and revoking any active sessions or tokens. Directory disablement blocks new logins across connected systems, and session revocation closes the gap for already-authenticated connections. Password changes, payroll-only removal, or delayed deletion all leave exploitable access in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the employee from the payroll system only.

    Why it's wrong here

    Payroll removal affects compensation processing but does not revoke access to email, applications, VPN, or cloud services. The account likely remains enabled in the directory. Access termination requires disabling the identity and revoking sessions, not just stopping pay.

  • ✗

    Schedule the account for deletion at the next quarterly access review.

    Why it's wrong here

    Waiting until a quarterly review leaves the terminated employee with valid access for weeks or months, which is unacceptable risk. Deletion also removes audit evidence that may be needed. Immediate disablement with later archival is the correct sequence.

  • ✓

    Disable the user account in the central directory and revoke active sessions and tokens.

    Why this is correct

    Disabling the directory account stops new authentications, while revoking sessions and tokens terminates existing access that would otherwise persist. Together they provide immediate, comprehensive revocation across federated and single sign-on systems. This is the standard offboarding action for prompt access removal.

  • ✗

    Change the employee's password and notify the manager of the new credential.

    Why it's wrong here

    Changing a password without disabling the account leaves the identity active and creates a shared credential risk if the manager uses it. Existing sessions and tokens may also remain valid. This does not reliably terminate access and can introduce accountability problems.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.