SY0-701 exam dumps

SY0-701 practice question 409 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 409

Single answerProcedures: Change management , Onboarding/offboarding , Playbooks

A company recently had a terminated employee use a still-active VPN account to access internal systems after business hours. During the post-incident review, the security manager finds that HR records the employee's departure date, IT disables accounts manually when notified, and there is no documented checklist for account removal or validation. The manager wants to reduce the chance of this happening again while improving consistency across future employee departures. Which action would BEST address the root cause?

  1. A

    Implement a formal offboarding playbook that requires HR-triggered notifications, documented account deprovisioning steps, and verification that access has been removed

  2. B

    Require administrators to change all shared passwords at the end of each week in case a departed employee still knows them

  3. C

    Increase VPN logging retention so the company can investigate future misuse by terminated employees more thoroughly

  4. D

    Allow department managers to send informal email requests to IT when an employee leaves, since managers usually know about departures before HR

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement a formal offboarding playbook with clear triggers, assigned responsibilities, and verification steps. The scenario identifies a classic procedural weakness: HR and IT are operating separately, deprovisioning is manual, and no checklist or validation exists. A documented offboarding playbook addresses this by defining who initiates the process, what systems must be updated, what access must be removed, and how completion is confirmed. This aligns with common security best practices such as least privilege, timely deprovisioning, separation of duties, and maintaining an auditable process. In practice, organizations often integrate HR events with identity and access management workflows so departures trigger standardized account disablement, badge revocation, token invalidation, and manager sign-off. While logging and password changes can be useful supporting controls, they do not fix the root procedural gap. This question also touches on change management principles because process changes that affect identity lifecycle management should be documented, approved, and consistently followed.

  • A. Correct.

    Correct. This directly addresses the process failure that allowed access to remain active. A formal offboarding playbook standardizes the sequence of actions, defines ownership, ensures HR or another authoritative source initiates the process, and includes validation steps to confirm account disablement, token revocation, and removal of access. In Security+ terms, this is the strongest procedural control because it improves consistency, accountability, and timely execution.

  • B. Incorrect.

    Incorrect. Rotating shared passwords may reduce some residual risk, but it does not solve the main issue: an individual account remained active because the offboarding process was inconsistent and manual. It also suggests continued use of shared credentials, which is generally weaker than unique accounts with proper access revocation.

  • C. Incorrect.

    Incorrect. More logging helps with detection and forensic review, but it is a detective control, not the best corrective or preventive action for the root cause. The incident occurred because offboarding was not formally documented or consistently executed, not because logs were unavailable.

  • D. Incorrect.

    Incorrect. Informal email-based requests are prone to delay, omission, and lack of auditability. They do not provide the structured workflow, approval trail, or verification steps expected in effective change management and offboarding procedures. Relying on informal communication increases the likelihood of the same failure recurring.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam