SY0-701 exam dumps

SY0-701 practice question 378 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 378

Single answer

A company is moving to an automated joiner/mover/leaver process for cloud and SaaS accounts. The security team wants new developers to receive access quickly, but only after controls are enforced consistently. The team also wants any exceptions to be reviewed and tracked automatically. Which solution BEST meets these requirements?

  1. A

    Use an HR-triggered workflow that calls identity and cloud provider APIs to provision accounts, adds users to role-based security groups, applies baseline guard rails to new resources, and automatically creates a ticket for any access request outside the approved role.

  2. B

    Allow each development manager to create accounts manually for new hires, then ask the security team to review permissions during the next monthly access review.

  3. C

    Create one shared administrator account for all new developers so they can start immediately, and disable the account only if suspicious activity is detected.

  4. D

    Provision all developer accounts automatically with full access to all cloud resources, then rely on the CI/CD pipeline to remove unnecessary permissions during later deployments.

Show answer and explanation

Correct answer: A

Explanation

The best answer is the workflow that combines user provisioning, security groups, guard rails, API-based integrations, and automated ticket creation for exceptions. In practice, organizations commonly integrate HR systems with identity providers and cloud platforms through APIs or automation tools to provision accounts when a user is hired or changes roles. Role-based security groups help enforce least privilege consistently, while guard rails reduce configuration drift and prevent noncompliant resource deployment. Automatic ticket creation supports approval, escalation, and auditability for requests that fall outside standard access models. This aligns with well-established best practices such as least privilege, separation of duties, and documented change/approval workflows. Relevant guidance can be found in NIST SP 800-53 controls related to account management and least privilege, as well as vendor identity lifecycle and cloud governance documentation describing automated provisioning, policy enforcement, and exception handling.

  • A. Correct.

    Correct. This approach uses automation and scripting in a way that aligns with Security+ objectives and operational best practices. An HR-triggered workflow is a common user provisioning pattern for joiner/mover/leaver processes. Calling identity and cloud APIs supports rapid, repeatable provisioning. Adding users to role-based security groups enforces least privilege through RBAC instead of ad hoc permissions. Applying baseline guard rails to resources helps ensure required controls, such as approved configurations or policy enforcement, are in place from the start. Automatic ticket creation for exceptions provides documented review and escalation paths rather than silently granting excessive access.

  • B. Incorrect.

    Incorrect. Manual account creation is slower, inconsistent, and prone to error. Delaying security review until a monthly access review creates a window of excessive or inappropriate access. This choice fails the requirement for quick but controlled provisioning and does not automate exception handling, ticket creation, or guard rail enforcement.

  • C. Incorrect.

    Incorrect. Shared administrator accounts violate accountability and least privilege. They prevent accurate attribution in logs and create major audit and incident response issues. Disabling access only after suspicious activity is detected is reactive rather than preventive and does not satisfy the requirement for consistent controls during provisioning.

  • D. Incorrect.

    Incorrect. Automatically granting full access conflicts with least privilege and creates unnecessary risk. CI/CD pipelines can support continuous integration and testing, but they are not intended to be the primary mechanism for correcting excessive user entitlements after accounts are provisioned. Permissions should be appropriately scoped at the time of user provisioning, with exceptions handled through review workflows.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam