Identity & Access Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity & Access Management flashcards as text
Multi-Factor Authentication (MFA) requires users to present verification from at least how many distinct authentication factor categories?
Answer: Two or more factors from different categories
MFA requires at least two distinct factor categories (e.g., something you know plus something you have), making authentication significantly more resistant to credential theft.
Which access control model makes access decisions based on data classification labels and user security clearances assigned by a central authority?
Answer: Mandatory Access Control (MAC)
MAC uses centrally controlled sensitivity labels on objects and clearance levels on subjects, with access determined by policy rather than owner discretion—commonly used in government environments.
Identity federation in the context of IAM refers to:
Answer: Linking a user's identity across multiple distinct identity management systems to enable cross-domain access
Identity federation allows users authenticated in one domain to access resources in a separate trusting domain without needing separate credentials, enabling seamless cross-organizational access.
Which open standard protocol is most commonly used to enable federated identity and authorization across different organizations and web applications?
Answer: SAML (Security Assertion Markup Language)
SAML is an XML-based open standard widely used for exchanging authentication and authorization data between an identity provider and a service provider in federated SSO scenarios.
What is the role of an Identity Provider (IdP) in a federated identity architecture?
Answer: It authenticates users and provides identity assertions to service providers
An IdP authenticates users and issues identity assertions or tokens (such as SAML assertions or OAuth tokens) that service providers trust to grant access without requiring separate authentication.
The principle of separation of duties (SoD) in IAM is primarily designed to prevent:
Answer: Fraud and errors by requiring more than one person to complete a sensitive task or transaction
Separation of duties ensures no single individual has enough access to complete a sensitive action alone, requiring collusion between multiple parties to commit fraud or cause significant errors.
Why are service accounts considered a significant identity and access management security risk in enterprise environments?
Answer: They often have excessive privileges, shared credentials, and infrequent password rotation
Service accounts frequently accumulate over-provisioned rights, use static passwords rarely rotated, and lack individual accountability, making them attractive targets for attackers seeking persistent elevated access.