← All CIAM Flashcard Decks

CIAM Audit and Monitoring Flashcards

6 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CIAM Audit and Monitoring flashcards as text
  1. What is 'segregation of duties' (SoD) in IAM?

    Answer: Ensuring no single person holds enough access rights to commit and conceal a fraudulent action alone

    Segregation of Duties ensures that sensitive processes require involvement from multiple individuals by distributing the necessary access rights across different people.

  2. What is a 'toxic combination' in access management?

    Answer: A set of access rights that together create an unacceptable security or fraud risk when held by one person

    A toxic combination is a set of permissions that, when granted to the same individual, violates segregation of duties — for example, having both payment creation and payment approval rights.

  3. What does 'log integrity' mean in IAM auditing?

    Answer: Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness

    Log integrity ensures audit records cannot be altered after creation, typically enforced through cryptographic controls, write-once storage, or tamper-evident log chains.

  4. What is the purpose of a recertification campaign in IAM?

    Answer: Periodically requiring managers to review and reconfirm that team members' access rights remain appropriate

    Recertification campaigns mandate that access rights be actively reconfirmed on a scheduled basis, rather than remaining in place indefinitely once granted.

  5. What is 'orphan account' detection in IAM?

    Answer: Identifying active accounts that remain after the associated employee has left or changed roles

    Orphan account detection identifies accounts that remain enabled after the associated user has been terminated or transferred, reducing the attack surface from stale credentials.

  6. What is the difference between authentication logging and authorization logging?

    Answer: Authentication logging records identity verification events; authorization logging records access control decisions

    Authentication logging captures login and logout events that verify identity, while authorization logging records access control decisions — what resources were allowed or denied to authenticated users.