SSCP Access Controls Practice Question
During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?
⚠ Common exam trap
The trap here is the manager's request to 'keep the account active for a week' — candidates who prioritize business convenience over security pick C or D, forgetting that immediate disablement plus file-ownership transfer satisfies both needs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the account immediately and transfer ownership of files to the manager
Best practice for offboarding is to disable the account immediately upon termination to eliminate the risk of unauthorized access, while preserving the account for audit and file-ownership purposes. File ownership and access to needed data should be transferred to the manager or another designated employee, satisfying the business need without keeping credentials live. This balances security with operational continuity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the account to a service account and keep it active
Why it's wrong here
Converting a personal account into a service account preserves standing, non-expiring credentials tied to a departed human, violating least privilege and orphaned-account controls. Service accounts are for workloads, not for manager file review; revoke and reassign access instead.
- ✓
Disable the account immediately and transfer ownership of files to the manager
Why this is correct
Disabling the account immediately satisfies the revocation constraint while preserving the data for review. Unlike deletion, which destroys the identity and its associated content, disabling blocks all authentication through Microsoft Entra ID yet allows an administrator to transfer file ownership to the manager, granting the week-long access without reactivating the former employee's credentials.
- ✗
Keep the account active but change the password and share it with the manager
Why it's wrong here
Sharing a password defeats individual accountability, since actions are logged against the former employee's identity and cannot be attributed. Revoke the account and grant the manager separate, time-limited access to the required files under their own credentials.
- ✗
Leave the account as-is and monitor activity for the week
Why it's wrong here
Retaining live credentials for a departed employee leaves an unmonitored, unauthorised access path; monitoring detects misuse only after it occurs. Immediate revocation with time-boxed, audited access granted to the manager satisfies the review need without preserving the account.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.