General Security Concepts1 / 5
A company wants to ensure that former employees cannot use their credentials to access cloud applications after termination. Which solution provides the MOST immediate and comprehensive access revocation?
CorrectIncorrect
Alex
Centralized identity management through an Identity Provider (IdP) enables unified access control across all connected applications. NIST SP 800-53 control PS-4 (Personnel Termination) requires organizations to revoke access promptly upon termination. Control enhancement AC-2(3) recommends automated mechanisms for account management. When automated deprovisioning is triggered (typically via HR integration), disabling one account immediately revokes all active SSO sessions and tokens, prevents new authentication, and triggers SCIM deprovisioning across connected SaaS apps. Without centralization, administrators must manually disable accounts in every application — a slow, error-prone process. Email requests, Wi-Fi changes, and password expiration are inadequate because they are not immediate, not comprehensive, and rely on the terminated employee's cooperation. Ref: NIST SP 800-53 Rev. 5, PS-4, AC-2(3).
Sourcelearn.microsoft.com
Follow-up answers are available in the app. Create a free account — no credit card required.
Question 1 of 5
Create a free account