Identity & Access Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity & Access Management flashcards as text
Privileged Access Management (PAM) solutions are primarily deployed to:
Answer: Manage and monitor the use of accounts with elevated administrative rights across enterprise systems
PAM controls, monitors, and audits privileged account usage to reduce the risk of insider misuse or external attackers leveraging compromised administrator credentials.
Access creep, a common IAM risk, occurs when:
Answer: Users accumulate more access rights over time than their current role requires, often due to role changes without access revocation
Access creep results from users retaining permissions from previous roles as they move through an organization, violating least privilege and increasing the organization's attack surface.
Just-In-Time (JIT) access provisioning is an IAM strategy that:
Answer: Grants elevated or sensitive access only when needed for a specific task and revokes it immediately afterward
JIT access eliminates standing privileges by granting temporary, task-specific elevated access on demand, significantly reducing the window of exposure if an account is compromised.
What is the key difference between authentication and authorization in the context of IAM?
Answer: Authentication verifies the identity of a user, while authorization determines what that verified identity is permitted to do
Authentication answers 'who are you?' by verifying identity credentials, while authorization answers 'what are you allowed to do?' by enforcing access control policies for the authenticated identity.
Under the CCISO exam framework, which domain most directly encompasses Identity and Access Management as a core competency area?
Answer: Domain 3: Security Program Management & Operations
Domain 3 covers security program management and operations, which includes implementing and overseeing controls such as IAM as part of day-to-day security operations.
Which IAM process ensures that a new employee receives only the access rights necessary for their specific role on their first day of employment?
Answer: Joiner-Mover-Leaver (JML) provisioning — specifically the joiner workflow
The JML framework governs the identity lifecycle: the joiner process provisions appropriate role-based access at onboarding, the mover process adjusts access during role changes, and the leaver process revokes access at offboarding.
A CISO reviewing IAM metrics notices that 15% of user accounts have not been accessed in over 90 days. What is the most appropriate immediate action?
Answer: Disable or lock inactive accounts pending business justification review and formal reactivation process
Dormant accounts represent an attack surface; disabling them pending review follows least-privilege principles while avoiding accidental deletion of potentially needed accounts such as seasonal or project-based users.