exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 559 discussion

Actual exam question from Isaca's CRISC
Question #: 559
Topic #: 1
[All CRISC Questions]

Which of the following is the BEST method to ensure a terminated employee's access to IT systems is revoked upon departure from the organization?

  • A. Login attempts are reconciled to a list of terminated employees
  • B. A process to remove employee access during the exit interview is implemented
  • C. The human resources (HR) system automatically revokes system access
  • D. A list of terminated employees is generated for reconciliation against current IT access
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hussmohsin
Highly Voted 3 years, 5 months ago
it says revoked upon departure, so there is nothing like automation, i would say the answer is C
upvoted 11 times
...
Sbills
Highly Voted 3 years, 5 months ago
Human resource is not responsible for revoking the IT system access. It is IT dept. who does it. D is correct answer
upvoted 7 times
...
babadook13
Most Recent 1 month, 1 week ago
Selected Answer: C
The human resources (HR) system automatically revokes system access - This method is the most effective and reliable way to ensure that access is revoked immediately upon termination
upvoted 1 times
...
Staanlee
10 months, 2 weeks ago
Selected Answer: B
B. A process to remove employee access during the exit interview is implemented. The best method to ensure a terminated employee's access to IT systems is revoked upon departure from the organization is to "B. Implement a process to remove employee access during the exit interview." This approach involves integrating the termination process with the IT access management process, ensuring that access is revoked as part of the formal exit procedures. By addressing access removal during the exit interview, you can promptly and reliably revoke access when an employee leaves the organization. While the other options (reconciling login attempts, HR system automatically revoking access, generating a list for reconciliation) can contribute to access management, they might not be as direct and effective as implementing a process during the exit interview to ensure that access removal is an integral part of the employee departure process.
upvoted 1 times
...
mraiyan
1 year, 1 month ago
Selected Answer: B
Why "C" ? are we assuming that all systems are integrated with HR system ? or HR system is an authentication system for other systems (SSO). If the question indicates that HR credentials are used as a single sign on then "C" is true. "D" is a good option but needs efforts and not proactive. Having a solid termination process in place will ensure that all access has been revoked.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: C
Agree it is C. Tying revocation of access to the HRMS via an automated process is best in this case.
upvoted 1 times
...
Julianleehk
1 year, 5 months ago
should be C
upvoted 1 times
Julianleehk
1 year, 2 months ago
Maybe is B
upvoted 1 times
...
...
john_boogieman
1 year, 5 months ago
Selected Answer: C
The best method is always an automated process that revokes access when the employee is terminated, the reconciliation process does not itself revoke access.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago