IAM & Multi-Factor Authentication Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IAM & Multi-Factor Authentication flashcards as text
Which MFA method is considered MOST resistant to real-time phishing attacks?
Answer: FIDO2/WebAuthn hardware key
FIDO2/WebAuthn binds authentication to the specific origin domain, making real-time phishing ineffective because stolen credentials cannot be replayed on a different site.
What is the primary security risk of using SMS as an MFA factor?
Answer: SIM swapping attacks can redirect messages to an attacker
SIM swapping allows attackers to convince carriers to transfer a victim's phone number to an attacker-controlled SIM, intercepting all SMS messages including OTPs.
In a federated identity model, what role does the Identity Provider (IdP) play?
Answer: It authenticates users and issues tokens that Service Providers trust
The IdP authenticates users and issues assertions or tokens (e.g., SAML assertions, JWTs) that Service Providers accept as proof of authentication.
Which access control model assigns permissions based on user attributes and environmental conditions rather than predefined roles?
Answer: Attribute-Based Access Control (ABAC)
ABAC evaluates policies against attributes of the user, resource, and environment (e.g., time, location) to make dynamic access decisions.
What does 'just-in-time (JIT) provisioning' mean in the context of IAM?
Answer: User accounts are created automatically at the moment of first login via federation
JIT provisioning automatically creates a user account in the Service Provider the first time a user successfully authenticates through a federated identity system.
A user's TOTP app generates a code that the server rejects despite correct time sync. What is the MOST likely cause?
Answer: The TOTP secret was provisioned with an incorrect shared key
If the shared secret between the TOTP app and the server does not match, generated codes will never validate regardless of correct time synchronization.
Which protocol is specifically designed to delegate authorization (not authentication) between services?
Answer: OAuth 2.0
OAuth 2.0 is an authorization framework that allows a resource owner to grant limited access to their resources to a third party without sharing credentials.