nerdexam
CompTIA

SY0-301 · Question #576

An auditor's report discovered several accounts with no activity for over 60 days. The accounts were later identified as contractors' accounts who would be returning in three months and would need…

The correct answer is A. Disable unnecessary contractor accounts and inform the auditor of the update. Inactive contractor accounts should be disabled rather than deleted, preserving them for reactivation upon return while removing the security risk of unattended active accounts.

Security operations

Question

An auditor's report discovered several accounts with no activity for over 60 days. The accounts were later identified as contractors' accounts who would be returning in three months and would need to resume the activities. Which of the following would mitigate and secure the auditors finding?

Options

  • ADisable unnecessary contractor accounts and inform the auditor of the update.
  • BReset contractor accounts and inform the auditor of the update.
  • CInform the auditor that the accounts belong to the contractors.
  • DDelete contractor accounts and inform the auditor of the update.

How the community answered

(31 responses)
  • A
    77% (24)
  • B
    3% (1)
  • C
    13% (4)
  • D
    6% (2)

Why each option

Inactive contractor accounts should be disabled rather than deleted, preserving them for reactivation upon return while removing the security risk of unattended active accounts.

ADisable unnecessary contractor accounts and inform the auditor of the update.Correct

Disabling accounts removes the ability to authenticate while preserving all account settings, group memberships, and permissions, so they can be re-enabled when the contractors return. This satisfies both the auditor's concern about inactive account risk and the operational need to restore access without rebuilding accounts from scratch.

BReset contractor accounts and inform the auditor of the update.

Resetting passwords on active accounts does not address the security risk - the accounts remain enabled and could still be exploited.

CInform the auditor that the accounts belong to the contractors.

Simply informing the auditor without taking any remediation action does not mitigate the security finding and leaves the inactive accounts as an ongoing risk.

DDelete contractor accounts and inform the auditor of the update.

Deleting the accounts would require creating entirely new accounts with reconfigured permissions when the contractors return, introducing unnecessary administrative overhead when disabling is sufficient.

Concept tested: Lifecycle management of inactive user accounts

Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Topics

#inactive accounts#account management#contractor access#account lifecycle

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice