SSCP Access Controls Practice Question
What is the primary purpose of account deprovisioning in the account lifecycle?
⚠ Common exam trap
The trap is confusing deprovisioning with role modification or password policy enforcement — candidates forget that deprovisioning is specifically about terminating access while retaining records for audit and legal purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To immediately disable accounts and preserve evidence
Deprovisioning is the formal process of removing a user's access when they leave or change roles. Its primary purpose is to immediately disable accounts to prevent unauthorized access while preserving the account and associated data as evidence for audits, investigations, or legal holds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To modify user roles and permissions
Why it's wrong here
Modifying roles and permissions is the remit of access review or role change management, which adjusts rights for users who remain active; deprovisioning removes access entirely when the relationship ends. It tempts because both occur at lifecycle transitions, and during a transfer or promotion, adjusting permissions is the correct action.
- ✓
To immediately disable accounts and preserve evidence
Why this is correct
Deprovisioning immediately disables or removes access rights when a user leaves or changes roles, and retaining the account data preserves audit evidence for investigations. This containment-first approach satisfies the lifecycle requirement to revoke access promptly while keeping records intact for forensic or compliance review.
- ✗
To enforce password policies
Why it's wrong here
Deprovisioning removes or disables an account when access is no longer required, revoking entitlements and sessions. Password policy enforcement governs credential strength and rotation for active accounts, so it neither removes access nor addresses the leaver scenario. Password policy is the right control when hardening authentication for accounts that remain active.
- ✗
To create new user accounts
Why it's wrong here
Creating accounts is provisioning, the opposite end of the lifecycle; deprovisioning revokes or removes access once a user no longer requires it. It tempts because both are lifecycle events handled by the same identity administration process, and for a new joiner, account creation is the correct first step.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.