โ† All CIAM Flashcard Decks

Directory Services Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Directory Services flashcards as text
  1. What is the default port for LDAPS (LDAP over SSL/TLS)?

    Answer: 636

    LDAPS uses TCP port 636 for standard domain connections, while port 3269 is used for LDAPS connections to the Global Catalog.

  2. Which feature in Active Directory allows administrators to recover accidentally deleted objects without restoring from backup?

    Answer: Active Directory Recycle Bin

    The AD Recycle Bin, introduced in Windows Server 2008 R2, preserves deleted objects with all their attributes intact, allowing restoration through PowerShell or the ADAC.

  3. In LDAP, what does the 'scope' parameter 'subtree' mean in a search operation?

    Answer: Search the base entry and all entries in the subtree below it

    A subtree search returns the base entry and all entries in the entire subtree beneath it, which is the broadest search scope available.

  4. What is 'schema' in the context of directory services?

    Answer: The formal definition of object classes and attribute types the directory can store

    The schema defines the rules for what types of objects can exist, what attributes they can have, and what data types those attributes hold.

  5. Which protocol does Azure AD Connect use to synchronize identities from on-premises Active Directory to Azure AD?

    Answer: Microsoft Identity Integration Server protocol with AAD Sync rules

    Azure AD Connect uses its own synchronization engine with configurable sync rules to replicate objects from on-premises AD to Azure AD via the Microsoft sync protocol.

  6. What is the purpose of an 'Organizational Unit' (OU) in Active Directory?

    Answer: To group objects for the application of Group Policy and delegation of administrative control

    OUs are containers used to organize directory objects and are the smallest scope at which Group Policy can be linked and administrative permissions can be delegated.

  7. In a directory service context, what is 'federation' with an external IdP primarily used for?

    Answer: Allowing users from an external organization to authenticate using their own identity provider

    Directory federation enables cross-organizational single sign-on by establishing trust so that an external IdP can assert authenticated user identities to local services.