CISSP Practice Question: A multinational firm must prevent unauthorized access by former employees across distributed…
Correct Answer: A. Implement a centralized Identity and Access Management (IAM) system with automated user provisioning and deprovisioning.
Explanation (CISSP Manager Logic):
Automation eliminates human error and ensures security policies are enforced consistently across a distributed enterprise. Integrating IAM with HR workflows allows for real-time revocation of access upon termination, directly addressing the risk of unauthorized access by former employees.
By implementing this solution, you:
- Eliminate "orphan" accounts that increase the attack surface.
- Ensure scalability and consistency across global, remote locations.
- Improve compliance through verifiable, automated audit trails.
While the other options are relevant, they fall short because:
- B: Manual reviews are reactive and infrequent, failing to provide the immediate revocation needed to prevent retaliation.
- C: Manual IT processes are prone to administrative delays, creating a dangerous window of opportunity for unauthorized access.
- D: A 90-day inactivity window is too long to mitigate immediate risks and may disrupt legitimate users on leave.
Think like a manager:
Prioritize systemic, automated controls over manual processes to ensure security operations are reliable, repeatable, and scalable. Effective identity management requires aligning technical controls with business lifecycle events.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial