Courseiva
hardMultiple Choice

SSCP Practice Question: During an audit, it is discovered that a…

During an audit, it is discovered that a contractor’s account has read access to a financial database even though the contractor’s project ended six months ago. Which type of access control failure is this?

⚠ Common exam trap

Many candidates confuse 'inadequate authorization' (which is about granting excessive permissions) with 'poor account management' (which is about failing to revoke access when it is no longer needed), even though the original authorization was correct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Poor account management

The contractor's account retained access privileges after the project ended, which is a failure of the account lifecycle management process. Proper account management requires disabling or removing accounts when a user's role or affiliation changes, such as when a contract terminates. This is not an authorization or authentication issue, as the access was originally granted correctly but was not revoked in a timely manner.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inadequate authorization

    Why it's wrong here

    Authorization governs what an authenticated identity may access, but the failure here is that rights were never revoked, which is an account lifecycle or entitlement review issue. It is tempting because the contractor retains read access, yet authorization would be correct if rights were granted beyond the role's scope.

  • ✗

    Insufficient authentication

    Why it's wrong here

    Authentication verifies identity at login; the contractor authenticated legitimately, so the failure lies in rights not being revoked after project end. It is tempting because dormant accounts are often hijacked, making authentication the correct answer when credentials are shared or cracked.

  • ✗

    Weak password policy

    Why it's wrong here

    Password strength governs credential guessing resistance, not the persistence of granted rights after a project ends. It is tempting because weak passwords enable account compromise, which would be the correct diagnosis if the contractor's credentials had been cracked rather than simply left active.

  • ✓

    Poor account management

    Why this is correct

    Access persisting six months after the contractor's project ended indicates the account was never disabled or removed, which is poor account management rather than a permissions-design flaw. This satisfies the stem's constraint of stale contractor access, reflecting failed lifecycle processes for provisioning, review and timely deprovisioning.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.