← All CIAM Flashcard Decks

Authentication Methods Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Authentication Methods flashcards as text
  1. Which authentication weakness does multi-factor authentication (MFA) directly mitigate that single-factor authentication cannot?

    Answer: Compromised credentials from data breaches being used alone to gain access

    MFA ensures that a stolen or leaked password alone is insufficient for access, requiring the attacker to also compromise a second factor such as a hardware token or biometric.

  2. What is the function of an 'authentication context class reference' (acr) claim in an OpenID Connect ID token?

    Answer: To indicate the level of assurance or method used during authentication

    The acr claim in an OIDC ID token communicates the authentication context, such as whether MFA was used or the NIST assurance level achieved, enabling relying parties to enforce access policies.

  3. An attacker intercepts a one-time password sent via SMS before the legitimate user enters it. This attack is best classified as:

    Answer: SIM-swapping or SS7 interception attack

    SMS OTPs can be intercepted through SIM-swapping (social engineering the carrier) or SS7 protocol vulnerabilities that allow interception of SMS messages in transit.

  4. In IAM architecture, what is 'identity proofing' and how does it relate to authentication assurance levels?

    Answer: Identity proofing is the process of verifying claimed identity during enrollment, establishing the foundation for higher assurance authentication

    Identity proofing (as defined in NIST SP 800-63A) is the enrollment-time process of verifying that a person is who they claim to be, which sets the maximum achievable authentication assurance level.

  5. Which NIST 800-63B authenticator assurance level (AAL) requires the use of a phishing-resistant, hardware-bound authenticator?

    Answer: AAL3

    NIST AAL3 requires a hardware-based authenticator with verifier impersonation resistance (phishing-resistant), providing the highest level of authentication assurance.

  6. A developer is building a mobile app and needs to authenticate users without storing a client secret on the device. Which OAuth 2.0 flow is most appropriate?

    Answer: Authorization Code flow with PKCE

    Authorization Code with PKCE is designed for public clients (mobile and SPA apps) that cannot securely store a client secret, using a dynamically generated code verifier instead.

  7. What is the primary difference between authentication and authorization in an IAM system?

    Answer: Authentication verifies the identity of a user; authorization determines what actions they are permitted to perform

    Authentication answers 'Who are you?' by verifying identity credentials, while authorization answers 'What are you allowed to do?' by enforcing access control policies.