โ† All CIAM Flashcard Decks

Authorization Frameworks Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Authorization Frameworks flashcards as text
  1. In an ABAC system, which of the following is an example of an 'environmental attribute' used in an access control decision?

    Answer: Time of day or geographic location

    Environmental attributes capture contextual conditions such as time of day, network location, or device security posture at the moment of the access request.

  2. Which OAuth 2.0 token type is a short-lived credential used to access protected resources on behalf of a user?

    Answer: Access token

    An access token is a short-lived credential presented by the client to the resource server to access protected resources on behalf of the resource owner.

  3. Which policy combining algorithm in XACML returns 'Deny' if any applicable policy returns 'Deny'?

    Answer: Deny-overrides

    The Deny-overrides combining algorithm returns Deny if any applicable policy or rule evaluates to Deny, prioritizing denial over permit decisions.

  4. What is the purpose of token introspection (RFC 7662) in OAuth 2.0?

    Answer: To allow a resource server to validate and query metadata about a token

    Token introspection allows a resource server to query the authorization server to determine whether a token is active and retrieve its metadata such as scope and expiration.

  5. In the context of federated identity and authorization, what does a 'relying party' depend on?

    Answer: An identity provider's assertions about the user

    A relying party (RP) trusts and depends on assertions or claims from an identity provider (IdP) to make authentication and authorization decisions rather than managing identity itself.

  6. Which approach best describes 'least privilege' as applied to OAuth 2.0 scopes?

    Answer: Requesting only the minimum scopes necessary for the current operation

    Least privilege in OAuth 2.0 means requesting only the scopes required for the specific task at hand, minimizing the potential damage if the access token is compromised.

  7. What distinguishes 'coarse-grained' authorization from 'fine-grained' authorization?

    Answer: Coarse-grained controls access at a broad level (e.g., API access) while fine-grained controls specific data or operations

    Coarse-grained authorization makes broad allow/deny decisions (e.g., can access the HR API), while fine-grained authorization makes detailed decisions (e.g., can view salary data only for direct reports).