ISC2 CISSP Provisioning Deprovisioning Service Accounts And Privilege Lifecycle Practice Test

 

5 Identity and Access Management (IAM) • 26 original questions

This CISSP practice test focuses on provisioning deprovisioning service accounts and privilege lifecycle through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Contoso Financial is revising controls for its payment processing service. A review highlights Account access review for users, systems, and services. The business continuity lead must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The identity population includes 5,800 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 2

An auditor asks Lucerne Publishing to demonstrate how it handles Provisioning and deprovisioning in the software delivery pipeline. The privacy and compliance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The identity population includes 7,500 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 3

After a business change, Lamna Healthcare discovers that Service-account management is not handled consistently for the AI-assisted customer service platform. The security architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The identity population includes 9,200 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: B

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 4

Fourth Coffee is preparing a security decision for the global collaboration platform. The decision involves Role definition and transition. The security operations manager must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The identity population includes 1,800 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 5

During a risk workshop for the e-commerce application, the team identifies Privilege escalation and sudo auditing as the deciding issue. The business continuity lead is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The identity population includes 3,500 workforce, service, or device identities.

  1. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.

Option review:

A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 6

A control owner at Proseware Labs proposes a quick technical fix for Account access review for users, systems, and services in the clinical records environment. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The identity population includes 5,200 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: C

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 7

Southridge Media is standardizing security across several business units. The remote access service raises a question about Account access review for users, systems, and services. The security architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The identity population includes 6,900 workforce, service, or device identities.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while accounting for third-party and lifecycle dependencies.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while accounting for third-party and lifecycle dependencies.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 8

During a business continuity exercise, Adventure Works asks the security operations manager to address Provisioning and deprovisioning for its customer identity platform. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The identity population includes 8,600 workforce, service, or device identities.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while maintaining the organization’s stated risk appetite.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while maintaining the organization’s stated risk appetite.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 9

VanArsdel Energy is revising controls for its data analytics lake. A review highlights Service-account management. The business continuity lead must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The identity population includes 1,200 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while meeting the business objective with the least unnecessary operational complexity.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 10

An auditor asks Northwind Health to demonstrate how it handles Role definition and transition in the branch-office network. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The identity population includes 2,900 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while keeping the control sustainable for normal operations.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while keeping the control sustainable for normal operations.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 11

After a business change, Coho Insurance discovers that Privilege escalation and sudo auditing is not handled consistently for the industrial control network. The security architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The identity population includes 4,600 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring the decision can be repeated consistently across business units.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring the decision can be repeated consistently across business units.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 12

  1. Datum Analytics is preparing a security decision for the research data repository. The decision involves Account access review for users, systems, and services. The security operations manager must address the control objective while preserving clear accountability and audit evidence. Which option BEST reflects CISSP-level security practice? The identity population includes 6,300 workforce, service, or device identities.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  5. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: B

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while preserving clear accountability and audit evidence.

Option review:

A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while preserving clear accountability and audit evidence.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 13

During a risk workshop for the payment processing service, the team identifies Provisioning and deprovisioning as the deciding issue. The business continuity lead is expected to address the control objective while protecting sensitive data throughout the change. What is the MOST appropriate course of action? The identity population includes 8,000 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.

Correct answer: B

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while protecting sensitive data throughout the change.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while protecting sensitive data throughout the change.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 14

A control owner at City Power proposes a quick technical fix for Service-account management in the software delivery pipeline. The privacy and compliance lead must address the control objective while preserving availability of the critical business service. What should happen FIRST? The identity population includes 600 workforce, service, or device identities.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while preserving availability of the critical business service.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while preserving availability of the critical business service.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 15

Tailspin Logistics is standardizing security across several business units. The AI-assisted customer service platform raises a question about Role definition and transition. The security architect needs to address the control objective without replacing governance with a technology-only shortcut. Which action provides the BEST governance and security outcome? The identity population includes 2,300 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without replacing governance with a technology-only shortcut.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without replacing governance with a technology-only shortcut.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 16

During a post-incident improvement program, Alpine Sports asks the security operations manager to address Privilege escalation and sudo auditing for its global collaboration platform. The requirement is to address the control objective while keeping the process defensible to auditors and business owners. What should the organization do FIRST? The identity population includes 4,000 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the process defensible to auditors and business owners.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the process defensible to auditors and business owners.

B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 17

Fabrikam Manufacturing is revising controls for its e-commerce application. A review highlights Account access review for users, systems, and services. The business continuity lead must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The identity population includes 5,700 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: C

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while minimizing irreversible action until facts and authority are established.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 18

An auditor asks Trey Research to demonstrate how it handles Provisioning and deprovisioning in the clinical records environment. The privacy and compliance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The identity population includes 7,400 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 19

After a business change, Margie Travel discovers that Service-account management is not handled consistently for the remote access service. The security architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The identity population includes 9,100 workforce, service, or device identities.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management without granting broader privilege than the business need requires.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 20

Wide World Importers is preparing a security decision for the customer identity platform. The decision involves Role definition and transition. The security operations manager must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The identity population includes 1,700 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition without creating a new single point of failure.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 21

During a risk workshop for the data analytics lake, the team identifies Privilege escalation and sudo auditing as the deciding issue. The business continuity lead is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The identity population includes 3,400 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while ensuring that emergency access cannot become permanent access.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 22

A control owner at Litware Services proposes a quick technical fix for Account access review for users, systems, and services in the branch-office network. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The identity population includes 5,100 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: C

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Account access review for users, systems, and services while allowing independent verification of the control outcome.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Account access review for users, systems, and services in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 23

Humongous Insurance is standardizing security across several business units. The industrial control network raises a question about Provisioning and deprovisioning. The security architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The identity population includes 6,800 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: B

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while accounting for third-party and lifecycle dependencies.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Provisioning and deprovisioning while accounting for third-party and lifecycle dependencies.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Provisioning and deprovisioning in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 24

During a quarterly security review, Woodgrove Bank asks the security operations manager to address Service-account management for its research data repository. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The identity population includes 8,500 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while maintaining the organization’s stated risk appetite.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service-account management in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Service-account management while maintaining the organization’s stated risk appetite.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 25

Relecloud Systems is revising controls for its payment processing service. A review highlights Role definition and transition. The business continuity lead must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The identity population includes 1,100 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: A

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Role definition and transition while meeting the business objective with the least unnecessary operational complexity.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role definition and transition in this scenario.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Question 26

An auditor asks Contoso Financial to demonstrate how it handles Privilege escalation and sudo auditing in the software delivery pipeline. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The identity population includes 2,800 workforce, service, or device identities.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: D

Why: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Privilege escalation and sudo auditing in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. It directly addresses Privilege escalation and sudo auditing while keeping the control sustainable for normal operations.

Learning point: Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly. Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes.

Popular posts

img