🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company uses AWS IAM Identity Center (AWS SSO) to grant employees access to multiple AWS accounts that host sensitive customer data. User identities originate in the HR system, which updates an on-premises Active Directory (AD). Recently, auditors found that some former employees could still sign in for several hours or days after their termination because administrators had to disable the accounts manually. Which approach will BEST minimize the time a departed employee retains access while also reducing ongoing administrative effort?

  • Enable CloudTrail log monitoring and send weekly reports of inactive users to the security team for manual review and removal.

  • Implement an HR-driven identity-governance workflow that uses a SCIM connector to automatically disable the user in AWS IAM Identity Center and revoke active sessions as soon as the HR record changes to terminated.

  • Require managers to submit a help-desk ticket on the employee's last day so administrators can manually delete the user from AD and AWS accounts.

  • Reduce IAM user password-expiration time to seven days so any credentials remaining after departure will become unusable quickly.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot