Identity and Access Management in Cloud Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Identity and Access Management in Cloud flashcards as text
What is 'federated identity' in the context of CCSK cloud security?
Answer: Using a single identity across multiple systems through trust relationships between identity providers
Federated identity allows a single identity (from an IdP) to be trusted across multiple systems or cloud providers without separate credential sets.
In CCSK, what is the recommended approach to privileged access management (PAM) in cloud environments?
Answer: Use just-in-time (JIT) privilege elevation with full audit logging of privileged sessions
JIT privilege elevation grants elevated access only when needed and for a limited time, minimizing the window of exposure for privileged credentials.
What does CCSK identify as the primary risk of using long-lived API keys for cloud service authentication?
Answer: Long-lived keys increase the window of exposure if compromised and are often not rotated properly
Long-lived API keys that are never rotated represent a persistent credential risk — if leaked, they provide indefinite unauthorized access.
What is 'attribute-based access control' (ABAC) and how does it enhance cloud IAM?
Answer: Access control that uses user attributes (department, location, device) to make fine-grained access decisions
ABAC evaluates multiple attributes of the user, environment, and resource to make dynamic, context-aware access control decisions beyond simple role assignments.
According to CCSK, why is MFA (multi-factor authentication) especially critical for cloud management consoles?
Answer: Because management consoles provide broad control over all cloud resources, making them high-value targets
Cloud management consoles grant access to provision, modify, or delete infrastructure — a single compromised credential could give attackers control of the entire environment.
What is the purpose of 'service accounts' in cloud IAM and what is a common security mistake associated with them?
Answer: Service accounts provide machine-to-machine authentication; the mistake is granting them excessive permissions or using them interactively
Service accounts authenticate non-human workloads, but they are often over-privileged or misused as human accounts, creating unnecessary security risk.