SY0-501 · Question #237
An organization uses SSO authentication for employee access to network resources. When an employee resigns, as per the organization's security policy, the employee's access to all network resources…
The correct answer is C. Deny the former employee's request, as a password reset would give the employee access to. The best course of action is to deny the former employee's password reset request because their access to all network resources was terminated upon resignation, and granting a reset would violate the organization's security policy.
Question
An organization uses SSO authentication for employee access to network resources. When an employee resigns, as per the organization's security policy, the employee's access to all network resources is terminated immediately. Two weeks later, the former employee sends an email to the help desk for a password reset to access payroll information from the human resources server. Which of the following represents the BEST course of action?
Options
- AApprove the former employee's request, as a password reset would give the former employee
- BDeny the former employee's request, since the password reset request came from an external
- CDeny the former employee's request, as a password reset would give the employee access to
- DApprove the former employee's request, as there would not be a security issue with the former
How the community answered
(50 responses)- A16% (8)
- B8% (4)
- C72% (36)
- D4% (2)
Why each option
The best course of action is to deny the former employee's password reset request because their access to all network resources was terminated upon resignation, and granting a reset would violate the organization's security policy.
Approving the request is incorrect because the former employee's access was explicitly terminated as per policy, and re-enabling it via a password reset would violate that policy.
While the external origin might prompt verification, the primary reason for denial is that the employee's access was already terminated, making any password reset attempt for an inactive account illegitimate.
Denying the password reset request is the correct action because the organization's security policy states that a resigning employee's access to all network resources is terminated immediately. Reinstating access, even for a password reset, would violate this policy and introduce a security risk by potentially allowing unauthorized access to network resources.
Approving the request is incorrect as it directly contradicts the security policy requiring immediate termination of all access for resigned employees, thereby creating a security vulnerability.
Concept tested: Security Policy Enforcement in Offboarding
Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/user-lifecycle-management-concept
Topics
Community Discussion
No community discussion yet for this question.