🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company uses Azure AD to federate workforce identities with several AWS accounts through AWS IAM Identity Center (AWS SSO). A few legacy automation scripts still rely on IAM users that possess long-lived access keys. When HR marks an employee as terminated, an automated off-boarding workflow is triggered. Which single action best ensures the former employee can no longer invoke AWS APIs after their Azure AD account is disabled?

  • Invoke the IAM DeleteAccessKey API to remove every active access key assigned to the user.

  • Attach an explicit deny policy to the IAM user that blocks all actions except sts:AssumeRole.

  • Disable the user's Azure AD account so that expired SAML sessions automatically block all AWS access.

  • Enable CloudTrail Insights to flag any anomalous calls and investigate them manually.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot