SY0-701 exam dumps

SY0-701 practice question 345 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 345

Single answerProvisioning/de-provisioning user accounts

A company discovered that a recently terminated payroll administrator was still able to sign in to a cloud HR application several hours after leaving the organization. The investigation showed the employee's VPN account had been disabled, but their SaaS account remained active because HR notified IT by email and the de-provisioning task was missed during a busy period. The security manager wants to reduce the chance of this happening again while also ensuring employees receive only the access they need when hired or transferred. Which solution BEST addresses both requirements?

  1. A

    Implement an identity and access management workflow integrated with the HR system to automatically provision and de-provision accounts based on job status and role changes

  2. B

    Require all administrators to manually review every user account at the end of each week and disable any accounts that appear inactive

  3. C

    Deploy a network access control solution so terminated users cannot connect to the internal network even if some application accounts remain active

  4. D

    Enable multifactor authentication on the cloud HR application so former employees cannot log in without a second factor

Show answer and explanation

Correct answer: A

Explanation

The best answer is to automate provisioning and de-provisioning through an IAM workflow tied to an authoritative source such as the HR system. This is a standard best practice for joiner-mover-leaver account management because it reduces human delay and inconsistency, especially across multiple systems including SaaS applications. Pairing this with role-based access control ensures users are provisioned with appropriate access when hired or transferred, supporting least privilege. Guidance from NIST on digital identity and access management emphasizes centralized identity lifecycle management, timely disabling of accounts when personnel separate, and periodic review as a supplemental control rather than the primary mechanism. Weekly manual reviews, NAC, and MFA are useful controls in some contexts, but they do not best address both rapid de-provisioning and correct role-based provisioning.

  • A. Correct.

    Correct. Integrating identity and access management (IAM) or identity governance processes with the authoritative HR source supports the account lifecycle from hire to transfer to termination. This reduces delays and human error by automatically creating, modifying, and disabling accounts when employment status changes. Using role-based access control also helps ensure users receive only the privileges appropriate for their job function.

  • B. Incorrect.

    Incorrect. Periodic manual review can help detect stale accounts, but it does not adequately solve the core problem of timely de-provisioning after termination. A weekly review still leaves a significant window of exposure, and relying solely on manual effort is error-prone in busy environments.

  • C. Incorrect.

    Incorrect. Network access control (NAC) can restrict device or network connectivity, but it does not directly manage SaaS account lifecycle events. In this scenario, the risk remained because the cloud HR application account was still active. A user could potentially access that service from outside the corporate network if authentication remained valid.

  • D. Incorrect.

    Incorrect. Multifactor authentication improves login security, but it does not replace proper de-provisioning. A terminated employee may still possess the second factor or have enrolled devices, and the account would remain active unless it is disabled. MFA reduces some risk but does not address least privilege or automated joiner-mover-leaver processes.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam