CCP Identity & Access Management Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCP Identity & Access Management flashcards as text
What is the purpose of a Privileged Access Workstation (PAW) in an enterprise IAM strategy?
Answer: To isolate administrative tasks on a hardened, dedicated device
A PAW is a dedicated, hardened workstation used exclusively for privileged administrative tasks to prevent credential theft and lateral movement.
Which protocol allows network devices to centralize authentication, authorization, and accounting for remote access users?
Answer: RADIUS
RADIUS (Remote Authentication Dial-In User Service) centralizes AAA functions for network access, widely used for VPN and Wi-Fi authentication.
What distinguishes OAuth 2.0 from OpenID Connect (OIDC)?
Answer: OAuth 2.0 is for authorization; OIDC adds an identity layer on top for authentication
OAuth 2.0 handles delegated authorization (granting access to resources), while OIDC extends it with an ID token to provide authentication and user identity information.
Which concept in IAM separates duties so that no single user can complete a sensitive transaction alone, reducing fraud risk?
Answer: Separation of duties (SoD)
Separation of duties divides critical tasks among multiple individuals so that collusion is required to commit fraud or errors, serving as an internal control.
A security team wants to ensure that privileged sessions are recorded and can be played back for audit purposes. Which tool category addresses this requirement?
Answer: Privileged Access Management (PAM) solution
PAM solutions provide session recording, keystroke logging, and playback capabilities for privileged accounts, supporting forensic investigation and compliance audits.
What is the primary function of an Identity Provider (IdP) in a federated identity architecture?
Answer: To authenticate users and issue identity assertions to service providers
An IdP authenticates users and issues tokens or assertions that service providers trust, enabling SSO across multiple applications without separate credential stores.