nerdexam
Isaca

CRISC · Question #38

Which of the following would be the GREATEST concern for an IT risk practitioner when an employees.....

The correct answer is B. Unnecessary access permissions have not been removed.. The greatest concern for an IT risk practitioner when an employee leaves or changes roles is that unnecessary access permissions have not been removed. This poses a significant security risk due to potential unauthorized access or data breaches.

Submitted by naveen.iyer· Apr 18, 2026IT Risk Assessment

Question

Which of the following would be the GREATEST concern for an IT risk practitioner when an employees.....

Options

  • AThe organization's structure has not been updated
  • BUnnecessary access permissions have not been removed.
  • CCompany equipment has not been retained by IT
  • DJob knowledge was not transferred to employees m the former department

How the community answered

(15 responses)
  • A
    27% (4)
  • B
    60% (9)
  • C
    7% (1)
  • D
    7% (1)

Why each option

The greatest concern for an IT risk practitioner when an employee leaves or changes roles is that unnecessary access permissions have not been removed. This poses a significant security risk due to potential unauthorized access or data breaches.

AThe organization's structure has not been updated

An outdated organizational structure is an administrative issue that doesn't directly pose an immediate IT security risk related to a specific employee's access.

BUnnecessary access permissions have not been removed.Correct

Failure to remove unnecessary access permissions for a departed or role-changed employee creates a significant security vulnerability, as the former employee or an attacker leveraging their old credentials could potentially access sensitive systems and data without authorization. This directly impacts the principle of least privilege and can lead to data breaches or system compromise.

CCompany equipment has not been retained by IT

While company equipment not being retained is an asset management and potential data loss risk, it is generally less immediate and pervasive than the risk of active unauthorized system access through unrevoked permissions.

DJob knowledge was not transferred to employees m the former department

Lack of job knowledge transfer impacts operational continuity and efficiency but is not an IT security or risk management concern for an IT risk practitioner related to the employee's access.

Concept tested: Offboarding access revocation

Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Topics

#Access Control#Offboarding Procedures#IT Security Risk#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice