CIAM Audit and Monitoring Flashcards
6 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CIAM Audit and Monitoring flashcards as text
What is 'segregation of duties' (SoD) in IAM?
Answer: Ensuring no single person holds enough access rights to commit and conceal a fraudulent action alone
Segregation of Duties ensures that sensitive processes require involvement from multiple individuals by distributing the necessary access rights across different people.
What is a 'toxic combination' in access management?
Answer: A set of access rights that together create an unacceptable security or fraud risk when held by one person
A toxic combination is a set of permissions that, when granted to the same individual, violates segregation of duties — for example, having both payment creation and payment approval rights.
What does 'log integrity' mean in IAM auditing?
Answer: Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness
Log integrity ensures audit records cannot be altered after creation, typically enforced through cryptographic controls, write-once storage, or tamper-evident log chains.
What is the purpose of a recertification campaign in IAM?
Answer: Periodically requiring managers to review and reconfirm that team members' access rights remain appropriate
Recertification campaigns mandate that access rights be actively reconfirmed on a scheduled basis, rather than remaining in place indefinitely once granted.
What is 'orphan account' detection in IAM?
Answer: Identifying active accounts that remain after the associated employee has left or changed roles
Orphan account detection identifies accounts that remain enabled after the associated user has been terminated or transferred, reducing the attack surface from stale credentials.
What is the difference between authentication logging and authorization logging?
Answer: Authentication logging records identity verification events; authorization logging records access control decisions
Authentication logging captures login and logout events that verify identity, while authorization logging records access control decisions — what resources were allowed or denied to authenticated users.