Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?

⚠ Common exam trap

The trap here is the manager's request to 'keep the account active for a week' — candidates who prioritize business convenience over security pick C or D, forgetting that immediate disablement plus file-ownership transfer satisfies both needs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the account immediately and transfer ownership of files to the manager

Best practice for offboarding is to disable the account immediately upon termination to eliminate the risk of unauthorized access, while preserving the account for audit and file-ownership purposes. File ownership and access to needed data should be transferred to the manager or another designated employee, satisfying the business need without keeping credentials live. This balances security with operational continuity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the account to a service account and keep it active

    Why it's wrong here

    Converting a personal account into a service account preserves standing, non-expiring credentials tied to a departed human, violating least privilege and orphaned-account controls. Service accounts are for workloads, not for manager file review; revoke and reassign access instead.

  • ✓

    Disable the account immediately and transfer ownership of files to the manager

    Why this is correct

    Disabling the account immediately satisfies the revocation constraint while preserving the data for review. Unlike deletion, which destroys the identity and its associated content, disabling blocks all authentication through Microsoft Entra ID yet allows an administrator to transfer file ownership to the manager, granting the week-long access without reactivating the former employee's credentials.

  • ✗

    Keep the account active but change the password and share it with the manager

    Why it's wrong here

    Sharing a password defeats individual accountability, since actions are logged against the former employee's identity and cannot be attributed. Revoke the account and grant the manager separate, time-limited access to the required files under their own credentials.

  • ✗

    Leave the account as-is and monitor activity for the week

    Why it's wrong here

    Retaining live credentials for a departed employee leaves an unmonitored, unauthorised access path; monitoring detects misuse only after it occurs. Immediate revocation with time-boxed, audited access granted to the manager satisfies the review need without preserving the account.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.