CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A company's HR system automatically notifies the IT department whenever an employee's status changes to 'terminated.' Upon receiving this notification, the cloud IAM administrator immediately disables the employee's cloud accounts and revokes all access tokens. Which stage of the identity lifecycle does this action represent?

  1. ARecertification
  2. BProvisioning
  3. CDeprovisioning
  4. DAuthentication
Show answer & explanation

Correct answer: C. Deprovisioning

Deprovisioning is the final stage of the identity lifecycle where access rights and accounts are revoked when they are no longer needed, such as upon termination. Prompt deprovisioning prevents orphaned accounts that could be exploited by attackers or former employees.

Why the other options are wrong

  • A. Recertification is periodic review of existing access, not immediate revocation upon termination.
  • B. Provisioning is granting initial access when an identity is created, not revoking it.
  • D. Authentication is verifying identity at login, unrelated to account termination.

Deprovisioning

The IAM lifecycle stage where user accounts and access rights are disabled or removed once they are no longer needed, such as upon termination or role change.

  • Prevents orphaned accounts
  • Should occur immediately upon termination
  • Part of the identity and access lifecycle
  • Reduces attack surface and insider threat risk

Memory trick: 'Deprovision = Door Slammed Shut' the moment someone leaves.

More Governance, Risk, Compliance and Security questions