nerdexam
(ISC)2

SSCP · Question #382

A periodic review of user account management should not determine:

The correct answer is C. Strength of user-chosen passwords. A user account management review focuses on the lifecycle and authorization state of accounts: Are accounts still needed (B)? Do privileges match job roles per least privilege (A)? Are the approvals from management current (D)? These are all directly within scope of account…

Submitted by chen.hong· Apr 18, 2026Access Controls

Question

A periodic review of user account management should not determine:

Options

  • AConformity with the concept of least privilege.
  • BWhether active accounts are still being used.
  • CStrength of user-chosen passwords.
  • DWhether management authorizations are up-to-date.

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    7% (1)
  • C
    87% (13)

Explanation

A user account management review focuses on the lifecycle and authorization state of accounts: Are accounts still needed (B)? Do privileges match job roles per least privilege (A)? Are the approvals from management current (D)? These are all directly within scope of account management. Password strength (C) is a separate security concern handled through password policy enforcement, technical controls (minimum length, complexity rules), and dedicated password-auditing processes - not through an account management review. Including password strength auditing in an account management review conflates two distinct security processes.

Topics

#User Account Management#Account Reviews#Access Controls#Password Security

Community Discussion

No community discussion yet for this question.

Full SSCP Practice