CCP Identity & Access Management Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCP Identity & Access Management flashcards as text
Which IAM concept ensures that users are granted only the minimum permissions necessary to perform their job functions?
Answer: Least privilege
The principle of least privilege limits user access rights to only what is strictly required for their role, reducing the attack surface.
What protocol is most commonly used to enable Single Sign-On (SSO) across web applications using token-based assertions?
Answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) is the predominant standard for SSO, exchanging XML-based authentication and authorization assertions between identity providers and service providers.
An organization wants to verify a user's identity using something they know, something they have, and something they are. What is this called?
Answer: Multi-factor authentication (MFA)
Multi-factor authentication (MFA) combines two or more distinct authentication factors — knowledge, possession, and inherence — to strengthen identity verification.
Which access control model assigns permissions based on organizational roles rather than individual user identities?
Answer: Role-Based Access Control (RBAC)
RBAC groups users into roles and assigns permissions to those roles, simplifying administration and enforcing consistent access policies.
What is the primary security risk associated with orphaned accounts in an enterprise directory?
Answer: They provide attackers with valid credentials to exploit
Orphaned accounts belong to former employees or unused services and represent active credentials that attackers can leverage for unauthorized access.
Which IAM framework concept involves continuously verifying identity and device posture rather than trusting users once they are inside the network perimeter?
Answer: Zero Trust
Zero Trust operates on the principle of 'never trust, always verify,' requiring continuous validation of identity, device health, and context for every access request.