โ† All CIAM Flashcard Decks

Directory Services Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Directory Services flashcards as text
  1. Which LDAP attribute is used to store the distinguished name of a group's members in Active Directory?

    Answer: member

    The 'member' attribute on a group object stores the DNs of its members, while 'memberOf' is a back-link attribute on the user object.

  2. What is the purpose of the Global Catalog in Active Directory?

    Answer: Provides a partial replica of all objects in the forest to enable cross-domain searches

    The Global Catalog holds a partial, read-only replica of all objects across all domains in the forest, enabling fast cross-domain searches without referrals.

  3. In an LDAP directory, what does a 'referral' response indicate?

    Answer: The directory server does not hold the requested entry and points to another server

    A referral (result code 10) tells the client that the target server does not have the requested data and provides a URL pointing to a server that may.

  4. Which replication topology model does Active Directory Sites and Services use by default to connect domain controllers?

    Answer: KCC-generated spanning tree

    The Knowledge Consistency Checker (KCC) automatically generates a bidirectional ring/spanning-tree replication topology between domain controllers within and between sites.

  5. What does the 'tombstoneLifetime' attribute in Active Directory control?

    Answer: How long deleted objects are retained before being permanently purged

    Tombstone lifetime defines how long deleted objects remain in the directory (default 180 days) so replication can propagate deletions before the object is fully purged.

  6. Which LDAP operation is used to move an entry from one part of the directory tree to another?

    Answer: ModifyDN

    The ModifyDN operation changes an entry's RDN or moves it to a new parent DN, effectively relocating it within the directory information tree.

  7. In Azure Active Directory, what is the function of 'Pass-through Authentication' (PTA)?

    Answer: Validates user passwords directly against on-premises AD in real time

    PTA forwards sign-in requests to lightweight on-premises agents that validate the password directly against local AD without storing any credentials in Azure.