nerdexam
(ISC)2

CISSP · Question #559

Which of the following is the final phase of the identity and access provisioning lifecycle?

The correct answer is B. Revocation. Revocation is the final phase of the identity and access provisioning lifecycle. The identity and access provisioning lifecycle is the set of activities and stages that govern the creation, modification, and deletion of user accounts and access privileges in an organization. The

Submitted by khalil_dz· Mar 5, 2026Identity and Access Management (IAM)

Question

Which of the following is the final phase of the identity and access provisioning lifecycle?

Options

  • ARecertification
  • BRevocation
  • CRemoval
  • DValidation

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    89% (33)
  • C
    5% (2)
  • D
    3% (1)

Explanation

Revocation is the final phase of the identity and access provisioning lifecycle. The identity and access provisioning lifecycle is the set of activities and stages that govern the creation, modification, and deletion of user accounts and access privileges in an organization. The identity and access provisioning lifecycle consists of six phases: request, approval, provision, test, review, and audit. Revocation is the process of terminating or disabling the user accounts and access privileges when they are no longer needed, used, or authorized, such as when a user leaves the organization, changes roles, or violates the policies. Revocation can be done manually or automatically, depending on the triggers and the mechanisms used. Revocation ensures that the user accounts and access privileges are removed in a timely and secure manner, and that the principle of least privilege and the separation of duties are maintained.

Topics

#IAM lifecycle#access revocation#deprovisioning#identity management

Community Discussion

No community discussion yet for this question.

Full CISSP Practice