CIAM – Certified Identity and Access Manager — Questions and Answers
Question 1: In RBAC, what term describes the assignment of a role to a user that allows the user to exercise the role's permissions?
- Permission assignment
- User-Role Assignment (URA) (Correct answer)
- Delegation
- Role activation
Correct answer: User-Role Assignment (URA)
User-Role Assignment (URA) is the relationship in RBAC that maps users to roles, granting them all permissions associated with those roles.
Question 2: A quarterly access review where managers certify their team's entitlements is best described as which compliance control?
- Separation of duties enforcement
- Role-based access control implementation
- Privileged access management audit
- User access recertification (UAR) (Correct answer)
Correct answer: User access recertification (UAR)
User Access Recertification (UAR) is a periodic review process where data owners or managers certify that access rights remain appropriate.
Question 3: The principle that a subject should only access resources necessary for their assigned tasks is called:
- Defense in Depth
- Separation of Duties
- Least Privilege (Correct answer)
- Job Rotation
Correct answer: Least Privilege
Least Privilege restricts subjects to only the minimum access rights required to perform their job functions, reducing the attack surface.
Question 4: In SAML, what is an 'assertion'?
- A public key certificate issued by a CA
- A password hash used for authentication
- A firewall rule granting access
- An XML statement conveying information about a subject's identity and attributes (Correct answer)
Correct answer: An XML statement conveying information about a subject's identity and attributes
A SAML assertion is an XML-based statement issued by an Identity Provider that conveys identity, attribute, and authorization decision information about a subject.
Question 5: In a hybrid IAM environment, what is the typical role of an 'identity bridge' or 'federation gateway'?
- To enforce MFA at the network perimeter
- To store user credentials in an encrypted vault
- To synchronize passwords between cloud and on-premises directories
- To translate between different identity protocols (e.g., Kerberos on-prem to SAML/OIDC in cloud) (Correct answer)
Correct answer: To translate between different identity protocols (e.g., Kerberos on-prem to SAML/OIDC in cloud)
An identity bridge or federation gateway converts authentication assertions between protocols, allowing on-premises Kerberos sessions to be federated to cloud services via SAML or OIDC.
Question 6: What is 'role explosion' in IAM governance?
- The uncontrolled proliferation of roles that makes access management complex and unmanageable (Correct answer)
- A denial-of-service attack targeting role management services
- A critical failure in role-based access control enforcement
- Server overload caused by processing too many role assignments simultaneously
Correct answer: The uncontrolled proliferation of roles that makes access management complex and unmanageable
Role explosion occurs when an organization creates an excessive number of overly granular roles, making role management, auditing, and governance impractical.
Question 7: Which attribute in Active Directory stores the last time a user successfully authenticated, and why is it sometimes disabled in large environments?
- accountExpires, because frequent updates exhaust the RID pool
- pwdLastSet, because storing login times violates privacy regulations
- lastLogonTimestamp, because it is updated too frequently and causes excessive replication
- lastLogon, because it is domain-controller-local and not replicated (Correct answer)
Correct answer: lastLogon, because it is domain-controller-local and not replicated
lastLogon is updated on every authentication but is NOT replicated between domain controllers, so each DC holds only its own view; lastLogonTimestamp is replicated but intentionally delayed.
Question 8: In identity governance, what is the 'entitlement catalog'?
- A record of all SoD violations found during the last review
- A centralized, searchable inventory of all available permissions and resources (Correct answer)
- A list of accounts that have been deprovisioned
- A log of all failed access requests
Correct answer: A centralized, searchable inventory of all available permissions and resources
The entitlement catalog provides a structured, business-friendly view of all permissions available for request, enabling self-service access management.
Question 9: Which type of attack specifically targets identity proofing systems by submitting fraudulent or stolen identity documents?
- Credential stuffing
- SQL injection
- Identity document fraud (Correct answer)
- Session hijacking
Correct answer: Identity document fraud
Identity document fraud involves presenting counterfeit, altered, or stolen documents during the proofing process in an attempt to fraudulently establish a new identity.
Question 10: Which principle requires that critical IAM tasks, such as provisioning and approving access, be divided between two or more individuals?
- Least privilege
- Defense in depth
- Zero trust
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties prevents a single person from having end-to-end control over a critical process, reducing fraud and error risk.
Question 11: A company processing EU citizen data from a U.S. data center must rely on which mechanism to legally transfer data under GDPR?
- ISO 27001 certification of the U.S. facility
- A signed NDA with the data processor
- EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) (Correct answer)
- GDPR Article 9 explicit consent only
Correct answer: EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs)
International data transfers from the EU to the U.S. require a valid transfer mechanism such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
Question 12: What is a common method for conducting a security audit within an IAM framework?
- Assigning roles to users based on their access needs
- Implementing a backup solution for user data
- Changing user passwords every 30 days
- Reviewing access logs to ensure compliance with access control policies (Correct answer)
Correct answer: Reviewing access logs to ensure compliance with access control policies
A common method for conducting a security audit within an IAM framework involves reviewing access logs. These logs provide a detailed record of who accessed what, when, and how, allowing organizations to verify compliance with access control policies and detect any unauthorized or suspicious activity.
Question 13: A 'ghost account' in IAM governance terminology refers to:
- A shared account used by multiple administrators
- An active account belonging to a user who no longer exists in the HR system (Correct answer)
- A service account with no assigned owner
- An account created for testing that was never deleted
Correct answer: An active account belonging to a user who no longer exists in the HR system
Ghost (or orphan) accounts are active user accounts that remain in the system after the associated employee has left, posing a significant security and compliance risk.
Question 14: In a DAC system, who ultimately controls access to a resource?
- The system administrator exclusively
- The mandatory security label
- The resource owner (Correct answer)
- The security policy engine
Correct answer: The resource owner
In DAC, the owner of a resource has discretion to grant or revoke access to other users, unlike MAC where the system enforces access centrally.
Question 15: Why is continuing education important in Authorization Frameworks?
- To stay current with evolving standards and practices (Correct answer)
- It is not important after certification
- To network only
- Only for re-certification requirements
Correct answer: To stay current with evolving standards and practices
Continuing education keeps professionals updated with the latest developments, standards, and best practices in their field.
Question 16: In IAM architecture, what is 'identity proofing' and how does it relate to authentication assurance levels?
- Identity proofing only applies to privileged administrative accounts
- Identity proofing is the process of verifying claimed identity during enrollment, establishing the foundation for higher assurance authentication (Correct answer)
- Identity proofing is the same as password reset verification
- Identity proofing is performed at every login to re-verify the user's documents
Correct answer: Identity proofing is the process of verifying claimed identity during enrollment, establishing the foundation for higher assurance authentication
Identity proofing (as defined in NIST SP 800-63A) is the enrollment-time process of verifying that a person is who they claim to be, which sets the maximum achievable authentication assurance level.
Question 17: What is the purpose of an identity lifecycle policy's 'dormancy' threshold?
- To determine how long audit logs are retained
- To define how long a password remains valid before expiry
- To set the maximum session duration for authenticated users
- To specify when an inactive account should be flagged or disabled (Correct answer)
Correct answer: To specify when an inactive account should be flagged or disabled
A dormancy threshold defines the period of inactivity after which an account is automatically flagged, disabled, or reviewed to reduce the attack surface.
Question 18: The SCIM (System for Cross-domain Identity Management) protocol is primarily used for which purpose?
- Signing SAML assertions for SSO
- Federating authentication between identity providers
- Automating user provisioning and deprovisioning across systems (Correct answer)
- Encrypting identity tokens in transit
Correct answer: Automating user provisioning and deprovisioning across systems
SCIM provides a standardized REST-based API for automating the exchange of user identity information between identity domains.
Question 19: What is the purpose of the audience restriction in a SAML assertion?
- To specify which Service Provider is authorized to consume the assertion (Correct answer)
- To restrict authentication to certain geographic regions
- To limit the token's validity period
- To limit the number of concurrent users
Correct answer: To specify which Service Provider is authorized to consume the assertion
The audience restriction in a SAML assertion specifies which Service Provider(s) may use it, preventing a valid assertion from being replayed at an unintended service.
Question 20: Which compliance requirement is primarily satisfied by implementing privileged access workstations (PAWs) for administrators?
- Privileged account isolation and protection (e.g., NIST SP 800-53 AC-6) (Correct answer)
- Network segmentation for PCI
- Data residency enforcement
- End-user password complexity
Correct answer: Privileged account isolation and protection (e.g., NIST SP 800-53 AC-6)
PAWs satisfy privileged access isolation requirements by providing a dedicated, hardened environment for administrative tasks, aligning with NIST AC-6 and similar controls.
Question 21: In identity lifecycle management, what distinguishes a 'mover' event from a 'joiner' event?
- Mover events create new accounts while joiner events modify existing ones
- Mover events require executive approval unlike joiner events
- Mover events apply only to contractors, not full-time staff
- Mover events involve role or department changes for existing employees (Correct answer)
Correct answer: Mover events involve role or department changes for existing employees
A mover event occurs when an existing employee changes roles, departments, or locations, requiring access adjustments rather than new account creation.
Question 22: What is 'Privileged Session Management' (PSM)?
- A capability that records, monitors, and controls sessions conducted by privileged users in real time (Correct answer)
- A browser session management tool for IT help desk staff
- A tool for managing end-user session timeouts
- A system for managing user authentication session tokens
Correct answer: A capability that records, monitors, and controls sessions conducted by privileged users in real time
Privileged Session Management records all keystrokes and actions during privileged user sessions, enabling real-time monitoring, intervention, and forensic replay after incidents.
Question 23: An organization needs fine-grained access control based on user department, time of day, and resource sensitivity. Which model best fits this requirement?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC) (Correct answer)
Correct answer: Attribute-Based Access Control (ABAC)
ABAC evaluates multiple attributes (user, environment, resource) simultaneously, making it ideal for complex, fine-grained policy requirements.
Question 24: What is 'orphan account' detection in IAM?
- Detecting anonymous guest accounts in directory services
- Finding shared service accounts with no designated owner
- Finding user accounts that lack assigned passwords
- Identifying active accounts that remain after the associated employee has left or changed roles (Correct answer)
Correct answer: Identifying active accounts that remain after the associated employee has left or changed roles
Orphan account detection identifies accounts that remain enabled after the associated user has been terminated or transferred, reducing the attack surface from stale credentials.
Question 25: Which of the following IAM tools is designed to manage privileged access to sensitive systems and resources?
- Privileged Access Management (PAM) (Correct answer)
- Virtual Private Network (VPN)
- Access Control Lists (ACLs)
- Identity Federation
Correct answer: Privileged Access Management (PAM)
PAM tools are designed to control and monitor access to critical systems by managing and securing privileged accounts. They help ensure that only authorized users have elevated access to sensitive resources.
Question 26: Which NIST publication provides the primary guidance for digital identity risk management and defines assurance levels?
- NIST SP 800-63 (Correct answer)
- NIST SP 800-37
- NIST SP 800-53
- NIST SP 800-30
Correct answer: NIST SP 800-63
NIST SP 800-63 defines Identity Assurance Level (IAL), Authenticator Assurance Level (AAL), and Federation Assurance Level (FAL).
Question 27: Which PCI DSS requirement specifically addresses the need to assign a unique ID to each person with computer access?
- Requirement 10
- Requirement 8 (Correct answer)
- Requirement 12
- Requirement 6
Correct answer: Requirement 8
PCI DSS Requirement 8 covers identification and authentication of access to system components, including assigning unique IDs.
Question 28: An organization wants to allow users to log in with their corporate credentials on a third-party SaaS application without sharing passwords. Which federation approach is most appropriate?
- LDAP direct bind
- Password vaulting
- SAML-based SSO (Correct answer)
- Basic HTTP authentication
Correct answer: SAML-based SSO
SAML-based SSO enables federated identity so users authenticate at the corporate IdP and the SaaS SP accepts the assertion, never receiving the user's password.
Question 29: In the context of IAM frameworks, which term describes the complete set of access rights, permissions, and privileges held by a specific user across all systems?
- Access footprint
- Entitlement inventory (Correct answer)
- Privilege manifest
- Identity profile
Correct answer: Entitlement inventory
An entitlement inventory catalogs all access rights assigned to a user across every application, system, and resource in the environment.
Question 30: Which technology allows users to authenticate using multiple factors, such as something they know (password) and something they have (smartphone)?
- Public Key Infrastructure (PKI)
- Single Sign-On (SSO)
- Kerberos Authentication
- Multi-factor Authentication (MFA) (Correct answer)
Correct answer: Multi-factor Authentication (MFA)
MFA requires two or more forms of verification, such as a password (something you know) and a one-time code sent to a phone (something you have). This provides stronger security than traditional authentication methods.
Question 31: What is the significance of a 'threat actor' in risk management for CIAM systems?
- An internal developer who writes authentication code
- An automated bot that monitors system uptime
- A regulatory body that audits IAM compliance
- An entity or group with the intent and capability to exploit vulnerabilities (Correct answer)
Correct answer: An entity or group with the intent and capability to exploit vulnerabilities
A threat actor is any individual, group, or organization with the motivation and capability to attack a system.
Question 32: Which IAM tool feature automatically removes access rights when an employee changes roles or departments?
- Multifactor enrollment
- Directory synchronization
- Automated deprovisioning / role reconciliation (Correct answer)
- Role explosion detection
Correct answer: Automated deprovisioning / role reconciliation
Automated deprovisioning or role reconciliation ensures access rights are adjusted when HR systems report a role change.
Question 33: A CIAM administrator discovers that a third-party identity provider (IdP) has suffered a breach. What is the FIRST step to take?
- Notify all end users immediately
- Revoke or invalidate all active sessions and tokens issued by that IdP (Correct answer)
- Shut down the entire CIAM platform
- Conduct a penetration test
Correct answer: Revoke or invalidate all active sessions and tokens issued by that IdP
Revoking active sessions and tokens from the compromised IdP immediately stops attackers from leveraging stolen credentials.
Question 34: When evaluating a PAM vendor, which capability ensures that privileged credentials are rotated immediately after each use?
- Session tokenization
- Credential brokering
- One-time password (OTP) for privileged accounts (Correct answer)
- Continuous password rotation
Correct answer: One-time password (OTP) for privileged accounts
OTP-based privileged access generates a unique password for each session, invalidating it immediately after the session ends.
Question 35: A governance board wants to reduce identity-related risk without increasing operational burden. Which IAM initiative best balances both goals?
- Removing all standing privileged access and requiring re-approval daily
- Requiring all users to request access through a help desk ticket
- Implementing risk-based access certification that focuses reviews on high-risk accounts (Correct answer)
- Expanding manual quarterly reviews to all user populations
Correct answer: Implementing risk-based access certification that focuses reviews on high-risk accounts
Risk-based certification focuses review effort on the highest-risk accounts and entitlements, reducing compliance burden while improving overall risk posture.
Question 36: What is encryption?
- Compressing files
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Backing up data
- Deleting data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 37: What is the primary purpose of a privileged access workstation (PAW)?
- To provide a hardened, isolated environment for performing administrative tasks (Correct answer)
- To centralize password storage
- To increase bandwidth for admin tasks
- To replace multi-factor authentication for admins
Correct answer: To provide a hardened, isolated environment for performing administrative tasks
A PAW is a dedicated, hardened workstation used exclusively for privileged tasks, reducing the attack surface for credential theft.
Question 38: A healthcare organization must ensure that only authorized workforce members access ePHI based on their job function. Which HIPAA concept does this describe?
- Minimum necessary standard (Correct answer)
- De-identification of PHI
- Break-glass access procedure
- Role-based access control
Correct answer: Minimum necessary standard
The HIPAA Minimum Necessary standard requires covered entities to limit access to ePHI to only what is needed for the workforce member's job function.
Question 39: A company wants to implement continuous authentication that monitors user behavior throughout a session, not just at login. Which technology approach supports this?
- One-time passwords sent at login only
- Behavioral biometrics and anomaly detection (Correct answer)
- Static session tokens with long expiry
- Basic authentication headers on every request
Correct answer: Behavioral biometrics and anomaly detection
Behavioral biometrics (typing patterns, mouse movements) and ML-based anomaly detection can continuously verify user identity throughout a session beyond the initial login event.
Question 40: What is a firewall?
- A password manager
- A fire-resistant building component
- An antivirus program
- A security device that monitors and controls network traffic based on rules (Correct answer)
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 41: Which process ensures that users only retain access rights that are still required for their current job function?
- Role mining
- Segregation of duties
- Privilege escalation
- Access certification (Correct answer)
Correct answer: Access certification
Access certification (also called access review or recertification) periodically validates that user entitlements remain appropriate for their current role.
Question 42: What is the key difference between account disablement and account deletion in offboarding workflows?
- Disablement is permanent while deletion allows recovery
- Deletion is faster and preferred for all offboarding scenarios
- Disablement applies to contractors only; deletion applies to employees
- Disablement preserves the account and data for audit; deletion removes them (Correct answer)
Correct answer: Disablement preserves the account and data for audit; deletion removes them
Disabling an account blocks access while retaining the account and associated data for audit trails, litigation holds, and knowledge transfer; deletion is irreversible.
Question 43: An organization's CIAM platform stores PII for millions of customers. Which regulation primarily governs data breach notification requirements in the United States at the federal level for financial institutions?
- GLBA Safeguards Rule (Correct answer)
- CCPA
- GDPR
- HIPAA Privacy Rule
Correct answer: GLBA Safeguards Rule
The GLBA Safeguards Rule (amended 2023) requires financial institutions to notify the FTC within 30 days of a breach affecting 500+ customers.
Question 44: Which access control model concept requires that a transaction be completed entirely or not at all, supporting data integrity?
- Clark-Wilson Integrity Model atomicity requirement (Correct answer)
- Bell-LaPadula Simple Security Property
- DAC owner delegation
- Biba no-write-up property
Correct answer: Clark-Wilson Integrity Model atomicity requirement
Clark-Wilson enforces well-formed transactions that are atomic, consistent, isolated, and durable (ACID properties), ensuring data integrity is maintained.
Question 45: What does 'non-repudiation' mean in the context of IAM auditing?
- Preventing unauthorized users from accessing the system
- Ensuring a user cannot deny having performed an authenticated action (Correct answer)
- Encrypting audit logs to protect their contents
- The ability to refuse an access request
Correct answer: Ensuring a user cannot deny having performed an authenticated action
Non-repudiation ensures that users cannot deny performing actions by providing cryptographically linked evidence tying actions to their authenticated identity.
Question 46: A SOC 2 Type II report differs from SOC 2 Type I primarily in that it:
- Is intended for regulatory bodies rather than customers
- Evaluates controls over a period of time rather than a point in time (Correct answer)
- Covers additional trust service criteria
- Requires third-party penetration testing
Correct answer: Evaluates controls over a period of time rather than a point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (typically 6–12 months), while Type I assesses design at a single point in time.
Question 47: What is the purpose of an IAM security dashboard?
- Tracking software license counts and renewal dates
- Managing server hardware resources and performance metrics
- Providing real-time visibility into identity and access health, risk indicators, and compliance status (Correct answer)
- Displaying marketing performance metrics for identity products
Correct answer: Providing real-time visibility into identity and access health, risk indicators, and compliance status
IAM dashboards consolidate key metrics such as failed logins, policy violations, orphan accounts, and certification status into a unified view for administrators.
Question 48: Which feature of modern IAM platforms allows policies to be expressed and evaluated in a standardized, human-readable policy language?
- X.509 extensions
- RADIUS attributes
- XACML or OPA (Open Policy Agent) (Correct answer)
- LDAP filters
Correct answer: XACML or OPA (Open Policy Agent)
XACML and OPA are policy languages/engines that allow fine-grained, externalized authorization policies to be written and enforced consistently.
Question 49: Which security concept defines the maximum acceptable downtime for a CIAM authentication service before business operations are critically impacted?
- Recovery Point Objective (RPO)
- Mean Time to Repair (MTTR)
- Recovery Time Objective (RTO) (Correct answer)
- Service Level Agreement (SLA)
Correct answer: Recovery Time Objective (RTO)
RTO defines the maximum tolerable length of time a system can be offline before the impact becomes unacceptable to the business.
Question 50: Which NIST Cybersecurity Framework function most closely aligns with user access provisioning and deprovisioning processes?
- Protect (Correct answer)
- Identify
- Detect
- Respond
Correct answer: Protect
The Protect function of the NIST CSF covers identity management and access control, including provisioning and deprovisioning of user access.
Question 51: What is a SIEM system in the context of IAM monitoring?
- A certificate authority for issuing identity certificates
- A password management system for enterprise users
- A Security Information and Event Management system that aggregates and correlates security logs (Correct answer)
- A Single Identity Entry Module for centralizing accounts
Correct answer: A Security Information and Event Management system that aggregates and correlates security logs
A SIEM aggregates security logs from multiple sources, correlates events using rules and analytics, and provides real-time alerting for potential security incidents including IAM anomalies.
Question 52: What is a firewall?
- A security device that monitors and controls network traffic based on rules (Correct answer)
- A fire-resistant building component
- An antivirus program
- A password manager
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 53: What is Single Logout (SLO) in federated identity?
- Revoking all digital certificates issued to a user
- Logging out from one application while remaining logged in to others
- A protocol that terminates sessions across all federated service providers when a user logs out (Correct answer)
- Disabling a federation trust relationship between domains
Correct answer: A protocol that terminates sessions across all federated service providers when a user logs out
Single Logout (SLO) is a protocol that propagates a logout event across all federated Service Providers, terminating all of a user's sessions simultaneously.
Question 54: In the context of IAM governance, a Segregation of Duties (SoD) violation occurs when:
- A user activates more than one role in a session
- A user holds access rights that span the full lifecycle of a critical transaction (Correct answer)
- An administrator grants access without approval
- A role contains more than 50 permissions
Correct answer: A user holds access rights that span the full lifecycle of a critical transaction
SoD violations exist when one person can initiate, approve, and complete a sensitive transaction without any checks, enabling fraud or error without detection.
Question 55: What is phishing?
- A backup system
- A type of firewall
- A network scanning tool
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 56: Which UMA 2.0 role is responsible for setting policies that govern access to protected resources?
- Requesting Party
- Resource Owner (Correct answer)
- Authorization Server
- Resource Server
Correct answer: Resource Owner
In UMA 2.0, the Resource Owner sets policies at the authorization server to control who can access their resources and under what conditions.
Question 57: What is the difference between authentication logging and authorization logging?
- Authorization logging records password changes while authentication logging records role assignments
- There is no meaningful difference between the two types
- Authentication logging records identity verification events; authorization logging records access control decisions (Correct answer)
- Authentication logging is encrypted while authorization logging is stored in plain text
Correct answer: Authentication logging records identity verification events; authorization logging records access control decisions
Authentication logging captures login and logout events that verify identity, while authorization logging records access control decisions — what resources were allowed or denied to authenticated users.
Question 58: Which of the following is a key factor in ensuring compliance with privacy regulations such as GDPR in IAM?
- Using MFA for all users
- Encrypting user data during storage and transmission (Correct answer)
- Enabling SSO for all systems
- Implementing strong password policies
Correct answer: Encrypting user data during storage and transmission
Encrypting user data, both when it is stored (at rest) and when it is being transmitted, is a critical measure for protecting personal information. This practice helps ensure compliance with privacy regulations like GDPR by safeguarding sensitive data from unauthorized access and breaches.
Question 59: A CIAM platform uses JSON Web Tokens (JWTs) for session management. Which vulnerability arises when JWT signature verification is bypassed by setting the algorithm to 'none'?
- Token replay attack
- Cross-site request forgery
- Algorithm confusion attack (Correct answer)
- Session fixation
Correct answer: Algorithm confusion attack
The 'alg:none' algorithm confusion attack allows attackers to forge tokens by stripping signature validation entirely.
Question 60: When implementing ABAC, a policy stating 'Allow access if user.clearance >= resource.classification AND user.department == resource.owner_department' is an example of:
- An ABAC policy rule combining subject and resource attributes (Correct answer)
- A capability token
- An ACL entry
- A Mandatory Access Control label comparison
Correct answer: An ABAC policy rule combining subject and resource attributes
This is a classic ABAC policy rule that combines subject attributes (clearance, department) with resource attributes (classification, owner department) to make an access decision.
Question 61: What is a firewall?
- A security device that monitors and controls network traffic based on rules (Correct answer)
- A password manager
- A fire-resistant building component
- An antivirus program
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 62: What is the default port for LDAPS (LDAP over SSL/TLS)?
- 3268
- 636 (Correct answer)
- 389
- 3269
Correct answer: 636
LDAPS uses TCP port 636 for standard domain connections, while port 3269 is used for LDAPS connections to the Global Catalog.
Question 63: What is User Behavior Analytics (UBA) in IAM?
- A network traffic analysis and optimization tool
- A marketing tool for analyzing user preferences
- A security capability that detects anomalous user activity patterns indicating potential compromise (Correct answer)
- An employee productivity tracking and reporting system
Correct answer: A security capability that detects anomalous user activity patterns indicating potential compromise
UBA applies machine learning to establish baseline behavior patterns for each user and alerts when deviations occur, helping detect compromised accounts and insider threats.
Question 64: In the context of CIAM, why is LDAP's hierarchical directory structure sometimes less suitable than a flat-schema database for consumer identity storage?
- Consumer identity data is often highly varied and unstructured, fitting poorly into rigid schema-based hierarchies (Correct answer)
- LDAP directories cannot scale beyond one million entries
- LDAP cannot store email addresses or phone numbers required for consumer profiles
- LDAP does not support TLS encryption needed for consumer privacy regulations
Correct answer: Consumer identity data is often highly varied and unstructured, fitting poorly into rigid schema-based hierarchies
Consumer identity attributes vary widely across users and change frequently, which conflicts with the strict, schema-enforced object class model of traditional LDAP directories.
Question 65: What is multi-factor authentication (MFA)?
- Requiring two or more verification methods to confirm identity (Correct answer)
- Logging in from multiple devices
- Using multiple passwords
- Having multiple accounts
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 66: In Kerberos authentication, what is the role of the Key Distribution Center (KDC)?
- To issue tickets that allow users to authenticate to services without re-entering credentials (Correct answer)
- To store all user passwords in plaintext for verification
- To perform biometric verification for each service request
- To maintain a real-time list of active user sessions
Correct answer: To issue tickets that allow users to authenticate to services without re-entering credentials
The KDC issues Ticket Granting Tickets (TGTs) and service tickets, enabling users to authenticate to network services without transmitting passwords across the network.
Question 67: What does 'just-in-time (JIT) provisioning' mean in identity lifecycle management?
- Access rights are granted only during approved business hours
- An account is created automatically at the moment of a user's first authentication (Correct answer)
- Accounts are pre-provisioned 24 hours before a user's first login
- Provisioning is triggered only when an SLA breach is detected
Correct answer: An account is created automatically at the moment of a user's first authentication
JIT provisioning creates user accounts on-demand during the first authentication event, reducing administrative overhead and the risk of stale pre-provisioned accounts.
Question 68: Which principle states that a privileged user should only be able to access systems relevant to their specific administrative function?
- Least privilege
- Need-to-know (Correct answer)
- Separation of duties
- Defense in depth
Correct answer: Need-to-know
Need-to-know restricts access to information or systems based on whether access is necessary for the user's defined job function.
Question 69: What is 'privileged user monitoring'?
- Network-level monitoring of privileged user workstations
- Monitoring only non-administrative standard users
- A password complexity monitoring tool for admin accounts
- Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts (Correct answer)
Correct answer: Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts
Privileged user monitoring implements heightened audit controls including comprehensive logging, session recording, and real-time alerting specifically for high-privilege accounts.
Question 70: Which OAuth 2.0 flow is recommended for server-to-server authentication without user interaction?
- Authorization Code Flow
- Device Authorization Flow
- Client Credentials Flow (Correct answer)
- Implicit Flow
Correct answer: Client Credentials Flow
The Client Credentials Flow is designed for machine-to-machine authentication where no user is present and only client credentials are used.
Question 71: What does 'ephemeral credentials' mean in the context of cloud privileged access?
- Permanent API keys rotated annually
- Credentials shared among multiple cloud services
- Credentials stored in encrypted form indefinitely
- Short-lived, automatically expiring secrets generated on demand (Correct answer)
Correct answer: Short-lived, automatically expiring secrets generated on demand
Ephemeral credentials are temporary secrets with a short TTL, drastically reducing the risk window if they are compromised.
Question 72: Which control provides assurance that access granted to a user matches what was formally approved in the provisioning request?
- Provisioning reconciliation (Correct answer)
- Role mining
- Entitlement creep detection
- Recertification campaign
Correct answer: Provisioning reconciliation
Provisioning reconciliation compares what was approved in access requests against what was actually granted in target systems, identifying discrepancies.
Question 73: Which IAM governance activity should an organization perform quarterly to ensure privileged access remains appropriate?
- Penetration testing
- Certificate rotation
- Access certification (recertification) campaign (Correct answer)
- Password strength audit
Correct answer: Access certification (recertification) campaign
Quarterly access certification campaigns require managers to formally review and approve or revoke each employee's privileged access rights.
Question 74: What is the primary purpose of threat analysis in IAM?
- To identify potential security risks that could compromise access to systems and data (Correct answer)
- To ensure that the network is optimized for performance
- To evaluate the effectiveness of disaster recovery plans
- To improve the authentication methods used by the organization
Correct answer: To identify potential security risks that could compromise access to systems and data
The primary purpose of threat analysis in IAM is to proactively identify potential security risks and vulnerabilities that could compromise access to systems and data. By understanding these threats, organizations can develop strategies and controls to mitigate them before they can be exploited.
Question 75: In zero-trust architecture applied to CIAM, which statement BEST describes the core security assumption?
- Firewalls are sufficient to protect identity systems
- VPN connections grant full internal network access
- No user or device is trusted by default, and every access request must be continuously verified (Correct answer)
- All internal network users are trusted by default
Correct answer: No user or device is trusted by default, and every access request must be continuously verified
Zero trust operates on the principle of 'never trust, always verify,' requiring continuous validation of every access request regardless of network location.
Question 76: What is 'scope downscoping' in OAuth 2.0 token exchange (RFC 8693)?
- Requesting scopes that exceed the client's registered permissions
- Removing expired scopes from the authorization server's policy
- Automatically expanding scopes when access tokens are refreshed
- Issuing a new token with a reduced set of scopes from the original token (Correct answer)
Correct answer: Issuing a new token with a reduced set of scopes from the original token
Scope downscoping in token exchange means the newly issued token has fewer or more restricted scopes than the original token, applying least-privilege for specific delegated operations.
Question 77: What is 'access creep' and why is it a concern in identity lifecycle management?
- Unauthorized access obtained through phishing attacks
- Gradual reduction of access rights due to automation errors
- Accumulation of unnecessary privileges over time as roles change (Correct answer)
- Over-provisioning of birthright access during onboarding
Correct answer: Accumulation of unnecessary privileges over time as roles change
Access creep occurs when users accumulate permissions from previous roles that are never revoked, violating least privilege and increasing breach risk.
Question 78: In Azure Active Directory, what does 'Seamless Single Sign-On' (Seamless SSO) accomplish for domain-joined devices?
- It automatically signs users into Azure AD apps without requiring additional prompts when they are on the corporate network (Correct answer)
- It federates all Azure AD apps to use on-premises ADFS tokens
- It replaces password authentication with certificate-based login for all users
- It synchronizes desktop SSO session cookies to mobile devices
Correct answer: It automatically signs users into Azure AD apps without requiring additional prompts when they are on the corporate network
Seamless SSO uses Kerberos tickets obtained from on-premises AD to silently authenticate domain-joined machines to Azure AD, eliminating re-prompts on the corporate network.
Question 79: During the joiner process, which attribute is typically used as the authoritative source for creating a new digital identity in an IAM system?
- IT helpdesk ticket number
- Employee's personal email address
- Manager's approval email
- HR system employee record (Correct answer)
Correct answer: HR system employee record
The HR system serves as the system of record and authoritative source for new hire data used to create digital identities.
Question 80: What does 'log integrity' mean in IAM auditing?
- Compressing log files to reduce storage requirements
- Synchronizing log timestamps across distributed systems
- Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness (Correct answer)
- Ensuring audit logs are human-readable and well-formatted
Correct answer: Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness
Log integrity ensures audit records cannot be altered after creation, typically enforced through cryptographic controls, write-once storage, or tamper-evident log chains.
Question 81: Which authentication protocol uses security assertions in XML format to exchange authentication and authorization data between an identity provider and a service provider?
- OpenID Connect
- OAuth 2.0
- SAML 2.0 (Correct answer)
- Kerberos
Correct answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) uses XML-based assertions to convey authentication and authorization information between identity providers and service providers.
Question 82: A CIAM risk assessment reveals that a specific threat has a high likelihood but a low impact. How should this risk TYPICALLY be prioritized?
- Transferred entirely to a third party
- Accepted without any controls
- Treated as critical and addressed immediately
- Monitored and assigned a medium priority (Correct answer)
Correct answer: Monitored and assigned a medium priority
High likelihood combined with low impact generally places a risk in the medium priority range, requiring monitoring but not emergency response.
Question 83: Which metric best measures the effectiveness of an access review campaign?
- Percentage of certifications completed on time (Correct answer)
- Average password length across accounts
- Total number of users provisioned
- Number of roles defined in the IGA system
Correct answer: Percentage of certifications completed on time
Certification completion rate measures how thoroughly reviewers fulfilled their obligation to validate user access, directly indicating review effectiveness.
Question 84: What is multi-factor authentication (MFA)?
- Using multiple passwords
- Logging in from multiple devices
- Having multiple accounts
- Requiring two or more verification methods to confirm identity (Correct answer)
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 85: What is phishing?
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
- A backup system
- A type of firewall
- A network scanning tool
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 86: Which metric is most useful for measuring the effectiveness of an organization's offboarding process?
- Mean time to deprovision access after a termination event (Correct answer)
- Average password length for departing users
- Percentage of users enrolled in MFA
- Number of accounts created per quarter
Correct answer: Mean time to deprovision access after a termination event
Mean time to deprovision (MTTD) directly measures how quickly access is revoked after departure, indicating offboarding process efficiency and risk exposure.
Question 87: What is the purpose of the 'nonce' parameter in OpenID Connect authentication requests?
- To prevent replay attacks by binding the token to the specific request (Correct answer)
- To indicate the preferred authentication method
- To specify the desired scopes for the token
- To encrypt the ID token payload
Correct answer: To prevent replay attacks by binding the token to the specific request
The nonce is a random value included in the authentication request and embedded in the ID token, allowing the client to verify the token was issued in response to that specific request.
Question 88: Which privileged access control method limits what commands a sudo user can run by defining rules in a configuration file?
- Sudoers file (Correct answer)
- RBAC policy
- Group Policy Object
- Access control list
Correct answer: Sudoers file
The /etc/sudoers file defines granular rules specifying which users can run which commands with elevated privileges on Unix/Linux systems.
Question 89: What is the purpose of a 'tabletop exercise' in the context of CIAM incident response planning?
- To simulate a security incident scenario and walk through response procedures verbally (Correct answer)
- To physically test network failover hardware
- To perform live penetration testing on the CIAM platform
- To review and update user access permissions
Correct answer: To simulate a security incident scenario and walk through response procedures verbally
A tabletop exercise is a discussion-based simulation where participants talk through their response to a hypothetical incident without real-world execution.
Question 90: Which IGA concept describes assigning access based on a user's verified attributes such as department, location, and clearance level?
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC) (Correct answer)
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC)
Correct answer: Attribute-Based Access Control (ABAC)
ABAC grants access dynamically based on evaluated attributes of the user, resource, and environment, enabling fine-grained, contextual access decisions.
Question 91: Which risk-based authentication signal is most commonly used to detect an anomalous login attempt that warrants step-up verification?
- The user's password length
- The time since the user last changed their password
- The user's job title from HR system
- IP geolocation and device fingerprint changes (Correct answer)
Correct answer: IP geolocation and device fingerprint changes
Risk-based authentication engines primarily evaluate contextual signals like IP geolocation changes, unfamiliar devices, and unusual access patterns to flag suspicious logins.
Question 92: What is the primary purpose of an identity governance 'fulfillment' workflow?
- Detecting anomalous login behavior
- Encrypting identity data at rest
- Generating audit logs for compliance
- Automatically provisioning approved access requests (Correct answer)
Correct answer: Automatically provisioning approved access requests
Fulfillment workflows execute the provisioning actions (granting or revoking access) after an access request has been approved.
Question 93: In the context of IAM, what is the key security benefit of using hardware security keys (e.g., YubiKey) over SMS-based OTP?
- Hardware keys do not require enrollment
- Hardware keys work without an internet connection only
- Hardware keys are cheaper to deploy
- Hardware keys are immune to SIM-swapping and phishing attacks (Correct answer)
Correct answer: Hardware keys are immune to SIM-swapping and phishing attacks
Hardware security keys are phishing-resistant because they use origin-bound cryptographic challenges, and they cannot be compromised by SIM-swapping attacks that target SMS OTP.
Question 94: What is phishing?
- A type of firewall
- A network scanning tool
- A backup system
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 95: What is 'role creep' in the context of identity governance?
- The gradual accumulation of access rights beyond what a user needs (Correct answer)
- A role with too few members to justify maintenance
- Automatic role assignment triggered by HR system changes
- A role that spans multiple business units
Correct answer: The gradual accumulation of access rights beyond what a user needs
Role creep occurs when users accumulate privileges over time through job changes or project assignments without removal of previously granted rights.
Question 96: A CIAM vendor is granted access to production user data for troubleshooting. Which control BEST manages the security risk of this third-party access?
- Disabling logging for the vendor's session to improve performance
- Implementing just-in-time (JIT) privileged access with session recording and time-limited permissions (Correct answer)
- Allowing the vendor to self-manage their own account
- Providing the vendor with permanent admin credentials
Correct answer: Implementing just-in-time (JIT) privileged access with session recording and time-limited permissions
JIT privileged access grants temporary, audited access only when needed, minimizing the window of exposure from third-party vendors.
Question 97: In Privileged Access Management (PAM), what is a 'just-in-time' (JIT) access approach designed to prevent?
- Password reuse across privileged accounts
- Unauthorized federation of privileged accounts
- Standing persistent privileged access that increases attack surface (Correct answer)
- Certificate expiry for service accounts
Correct answer: Standing persistent privileged access that increases attack surface
JIT access grants elevated privileges only when needed and for a limited time, eliminating standing privileged accounts that attackers can exploit.
Question 98: What does a formal access rights review typically assess?
- Whether current user permissions align with job responsibilities and the least privilege principle (Correct answer)
- Software license compliance across the organization
- Network performance and bandwidth utilization
- Password complexity and strength across all accounts
Correct answer: Whether current user permissions align with job responsibilities and the least privilege principle
Access rights reviews compare users' current permissions against their actual job role requirements, identifying excessive, unused, or otherwise inappropriate access rights.
Question 99: In identity lifecycle management, what is a 'role explosion' risk?
- An unmanageable proliferation of fine-grained roles that increases complexity (Correct answer)
- Duplicate role definitions across multiple connected applications
- A security incident caused by overly broad role assignments
- Rapid growth in the number of user accounts beyond system capacity
Correct answer: An unmanageable proliferation of fine-grained roles that increases complexity
Role explosion occurs when organizations create too many granular roles, making role management, assignment, and certification unmanageable.
Question 100: In a federated identity model, which entity makes the authentication decision and asserts the user's identity to a relying party?
- The LDAP directory
- The relying party (RP)
- The Identity Provider (IdP) (Correct answer)
- The resource server
Correct answer: The Identity Provider (IdP)
The Identity Provider authenticates the user and issues assertions (e.g., SAML or OIDC tokens) to the relying party.
Question 101: Which risk treatment option involves purchasing cyber liability insurance to cover potential losses from an identity breach?
- Risk avoidance
- Risk transference (Correct answer)
- Risk mitigation
- Risk acceptance
Correct answer: Risk transference
Risk transference shifts the financial impact of a risk to a third party, such as an insurance provider.
Question 102: When implementing LDAP in a CIAM solution, what is the primary security concern with using simple bind authentication?
- Simple bind does not support multi-factor authentication
- Simple bind accounts cannot be assigned granular directory permissions
- Credentials are transmitted in cleartext unless TLS is also enforced (Correct answer)
- Simple bind sessions expire too quickly for consumer applications
Correct answer: Credentials are transmitted in cleartext unless TLS is also enforced
Simple bind sends the DN and password in plaintext over the network, making it vulnerable to credential interception unless the connection is protected by TLS/LDAPS.
CIAM – Certified Identity and Access Manager
The CIAM certification is offered by the Identity Management Institute and validates expertise in identity governance, access management, authentication, risk management, and regulatory compliance. The exam consists of 100 multiple-choice questions to be completed in 90 minutes with a 70% passing score.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds