← All ACL Flashcard Decks

Identity & Access Management Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity & Access Management flashcards as text
  1. In a mandatory access control (MAC) system, who controls access to resources?

    Answer: A central authority enforces policy based on classification labels

    MAC systems rely on a central authority that enforces access based on security labels and classifications, not individual owner discretion.

  2. What is an 'orphan account' in the context of identity lifecycle management?

    Answer: A user account that remains active after the associated employee has left the organization

    Orphan accounts are active user accounts that are no longer associated with a current employee, creating a security risk if not deprovisioned.

  3. Which protocol is most commonly used to query and manage directory services for user authentication in enterprise environments?

    Answer: LDAP

    LDAP (Lightweight Directory Access Protocol) is the standard protocol for accessing and maintaining directory information such as user accounts.

  4. A user can read a file but cannot modify it. Which type of permission has been applied?

    Answer: Read-only permission

    Read-only permission allows a user to view the contents of a file but prevents any modifications.

  5. What is 'privilege creep' in identity and access management?

    Answer: The gradual accumulation of access rights beyond what a user currently needs

    Privilege creep occurs when users accumulate access rights over time—often through role changes—without removing previously granted permissions.

  6. Which IAM control is specifically designed to verify that user access rights remain appropriate over time?

    Answer: Access certification (user access review)

    Access certification is a periodic review process where managers verify that users still need and are authorized for their current access rights.

  7. In attribute-based access control (ABAC), access decisions are made based on which of the following?

    Answer: Attributes of the user, resource, environment, and action being requested

    ABAC evaluates multiple attributes—user attributes, resource attributes, environmental conditions, and the action—to make fine-grained access decisions.

Identity & Access Management Flashcards — ACL Study Cards with Answers