SSCP Access Controls Practice Question
An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)
⚠ Common exam trap
SSCP often tests the boundary between provisioning and deprovisioning by offering role modification and account disabling as distractors, since candidates conflate all account changes with 'provisioning'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating user accounts in the identity store
Option A is correct because provisioning begins with creating the user account (identity) in the identity store, such as an LDAP directory or IdP, so the user has a unique identity to authenticate with. Option D is correct because provisioning also includes granting the initial entitlements — assigning the baseline role memberships and permissions the user needs on day one. Option B is not part of provisioning; modifying roles after a job change is a re-provisioning/change (mover) activity in the lifecycle. Option C is not part of provisioning; archiving user data for compliance belongs to the deprovisioning/retention phase. Option E is not part of provisioning; disabling accounts on termination is a deprovisioning (leaver) activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creating user accounts in the identity store
Why this is correct
Provisioning covers creating and placing identities into the store, so account creation is a core provisioning activity. It precedes ongoing maintenance tasks such as permission updates, reviews and eventual deprovisioning, satisfying the lifecycle phase the stem asks about.
- ✗
Modifying user roles due to job change
Why it's wrong here
Modifying roles due to a job change is a reprovisioning or maintenance activity, not initial provisioning. It is tempting because it adjusts entitlements, but provisioning establishes accounts and their starting access, whereas role changes alter existing accounts later in the lifecycle.
- ✗
Archiving user data for compliance
Why it's wrong here
Archiving user data for compliance occurs during deprovisioning or after account removal, not when accounts are created. It is tempting because it is a lifecycle activity tied to termination, but provisioning covers creating accounts and assigning initial access, not retaining data post-termination.
- ✓
Assigning initial role memberships and permissions
Why this is correct
Assigning initial role memberships and permissions occurs during provisioning, when the new identity is created and granted the access rights its job requires. This establishes least-privilege entitlements before the account becomes active, distinguishing provisioning from later review or deprovisioning activities.
- ✗
Disabling accounts upon termination
Why it's wrong here
Disabling accounts belongs to the deprovisioning phase, which revokes access after termination. It is tempting because it is a lifecycle activity that removes entitlements, but provisioning creates and configures accounts and their initial access, so disabling occurs later in the lifecycle.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.