Question

Difficulty: EasyIdentity and Access Management Operations

A security administrator receives an alert indicating that domain credentials belonging to a recently terminated employee were used to successfully log in to an internal server. Which of the following identity and access management (IAM) operational processes would have directly prevented this unauthorized access?

  1. Performing prompt account deprovisioning as part of the employee offboarding workflowAnswer
  2. B
    Modifying discretionary access control permissions assigned to the user's role
  3. C
    Restricting server login access exclusively to users connected via the internal perimeter VPN
  4. D
    Deploying a detective SIEM correlation rule to log successful authentication events

Answer

Performing prompt account deprovisioning during offboarding directly revokes authentication credentials, preventing terminated employees from logging in to network systems.
Account deprovisioning is an essential IAM operational process executed during offboarding to disable or remove user accounts immediately upon termination. Deactivating the account revokes identity rights and prevents former staff from authenticating to enterprise systems.

Step-by-Step Solution

1
Identify the operational vulnerability presented in the scenario.
The issue is an active identity credential belonging to a terminated worker.
When employment is terminated, user credentials must immediately cease to be valid for authentication.
2
Evaluate the appropriate preventive IAM lifecycle procedure.
Automated or timely account deprovisioning deactivates access rights and credentials.
Deprovisioning directly revokes identity access privileges at the authentication source.

Key Concept

Identity Lifecycle Management and Account Deprovisioning
Rate this question