โ† All CIAM Flashcard Decks

Authorization Frameworks Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Authorization Frameworks flashcards as text
  1. Which OAuth 2.0 grant type is specifically designed for machine-to-machine (M2M) communication where no user is involved?

    Answer: Client Credentials

    The Client Credentials grant type allows a client to authenticate with the authorization server using its own credentials and obtain an access token without user involvement.

  2. In XACML, which component is responsible for making the actual access control decision?

    Answer: Policy Decision Point (PDP)

    The Policy Decision Point (PDP) evaluates access requests against policies and returns an authorization decision (Permit, Deny, Indeterminate, or NotApplicable).

  3. What is the primary security risk of using implicit OAuth 2.0 flow in a Single Page Application (SPA)?

    Answer: Access tokens are exposed in the URL fragment and browser history

    In the implicit flow, access tokens are returned directly in the URL fragment, making them visible in browser history and vulnerable to interception via referrer headers.

  4. Which UMA 2.0 role is responsible for setting policies that govern access to protected resources?

    Answer: Resource Owner

    In UMA 2.0, the Resource Owner sets policies at the authorization server to control who can access their resources and under what conditions.

  5. In OAuth 2.0, what does the 'state' parameter protect against?

    Answer: Cross-Site Request Forgery (CSRF) attacks

    The 'state' parameter is an opaque value used to maintain state between the request and callback, primarily to prevent CSRF attacks against the client's redirect URI.

  6. Which authorization model assigns permissions based on a user's job function within an organization?

    Answer: Role-Based Access Control (RBAC)

    Role-Based Access Control (RBAC) grants permissions based on roles assigned to users, where roles correspond to job functions or responsibilities within the organization.

  7. What is PKCE (Proof Key for Code Exchange) designed to prevent in OAuth 2.0 public clients?

    Answer: Authorization code interception attacks

    PKCE prevents authorization code interception attacks by binding the authorization code to a dynamically generated code verifier known only to the legitimate client.