nerdexam
CompTIA

SY0-501 · Question #252

During a recent audit, it was discovered that several user accounts belonging to former employees were still active and had valid VPN permissions. Which of the following would help reduce the amount o

The correct answer is B. User access reviews. The audit discovered a critical security vulnerability where former employees retained active accounts and VPN access. Implementing regular user access reviews is the direct method to mitigate this risk by ensuring timely deactivation of unnecessary access.

Submitted by rania.sa· Mar 4, 2026Security operations

Question

During a recent audit, it was discovered that several user accounts belonging to former employees were still active and had valid VPN permissions. Which of the following would help reduce the amount of risk the organization incurs in this situation in the future?

Options

  • ATime-of-day restrictions
  • BUser access reviews
  • CGroup-based privileges
  • DChange management policies

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    72% (21)
  • C
    17% (5)
  • D
    3% (1)

Why each option

The audit discovered a critical security vulnerability where former employees retained active accounts and VPN access. Implementing regular user access reviews is the direct method to mitigate this risk by ensuring timely deactivation of unnecessary access.

ATime-of-day restrictions

Time-of-day restrictions limit when an active account can be used but do not address the fundamental issue of why a former employee's account remains active with valid permissions.

BUser access reviewsCorrect

User access reviews are a formal, periodic process to re-evaluate who has access to specific resources and why. By conducting these reviews regularly, an organization can identify and remove access for inactive accounts, such as those belonging to former employees, thereby preventing unauthorized access and reducing the risk of security breaches related to stale permissions.

CGroup-based privileges

Group-based privileges simplify access management by assigning permissions to groups, but they do not inherently ensure that users who leave the organization are removed from these groups or that their accounts are disabled.

DChange management policies

Change management policies govern the process of implementing controlled changes to IT systems and configurations, not the routine auditing and deactivation of user accounts based on employment status changes.

Concept tested: User Access Review for Lifecycle Management

Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Topics

#access management#user access reviews#offboarding#identity management

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice