nerdexam
CompTIA

SY0-501 · Question #237

An organization uses SSO authentication for employee access to network resources. When an employee resigns, as per the organization's security policy, the employee's access to all network resources…

The correct answer is C. Deny the former employee's request, as a password reset would give the employee access to. The best course of action is to deny the former employee's password reset request because their access to all network resources was terminated upon resignation, and granting a reset would violate the organization's security policy.

Submitted by kevin_r· Mar 4, 2026Security operations

Question

An organization uses SSO authentication for employee access to network resources. When an employee resigns, as per the organization's security policy, the employee's access to all network resources is terminated immediately. Two weeks later, the former employee sends an email to the help desk for a password reset to access payroll information from the human resources server. Which of the following represents the BEST course of action?

Options

  • AApprove the former employee's request, as a password reset would give the former employee
  • BDeny the former employee's request, since the password reset request came from an external
  • CDeny the former employee's request, as a password reset would give the employee access to
  • DApprove the former employee's request, as there would not be a security issue with the former

How the community answered

(50 responses)
  • A
    16% (8)
  • B
    8% (4)
  • C
    72% (36)
  • D
    4% (2)

Why each option

The best course of action is to deny the former employee's password reset request because their access to all network resources was terminated upon resignation, and granting a reset would violate the organization's security policy.

AApprove the former employee's request, as a password reset would give the former employee

Approving the request is incorrect because the former employee's access was explicitly terminated as per policy, and re-enabling it via a password reset would violate that policy.

BDeny the former employee's request, since the password reset request came from an external

While the external origin might prompt verification, the primary reason for denial is that the employee's access was already terminated, making any password reset attempt for an inactive account illegitimate.

CDeny the former employee's request, as a password reset would give the employee access toCorrect

Denying the password reset request is the correct action because the organization's security policy states that a resigning employee's access to all network resources is terminated immediately. Reinstating access, even for a password reset, would violate this policy and introduce a security risk by potentially allowing unauthorized access to network resources.

DApprove the former employee's request, as there would not be a security issue with the former

Approving the request is incorrect as it directly contradicts the security policy requiring immediate termination of all access for resigned employees, thereby creating a security vulnerability.

Concept tested: Security Policy Enforcement in Offboarding

Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/user-lifecycle-management-concept

Topics

#SSO#identity management#offboarding#access revocation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice