Case 731B1C · GRC · L3 Applied
Auditor Finds Orphaned Admins
Practise as: Incident drill · Interview
Live alertDuring SOC 2 Type II fieldwork, the auditor finds 3 employees terminated 45+ days ago whose Okta accounts are still active with AdministratorAccess to production AWS.
Interview questionAn auditor flags terminated users with live prod admin access. What do you do in the next 48 hours and after?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Contain now: suspend the Okta accounts, revoke sessions, rotate any access keys and remove IAM Identity Center assignments.
- Prove no misuse: review Okta System Log and CloudTrail for activity by those identities after termination date.
- Scope it: reconcile HRIS terminations against all IdP and direct-to-app accounts to find other orphans.
- Root cause: HR-to-IdP deprovisioning gap (manual ticket, missed SCIM). Automate via HRIS-driven SCIM.
- Give auditor a management response with remediation, evidence and date; expect a noted exception in the report.
If the interviewer pushes back
- If CloudTrail shows one of those accounts assumed a role last week, how does this change from audit finding to incident?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.