← All CIAM Flashcard Decks

Directory Services Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Directory Services flashcards as text
  1. What is the role of the 'PDC Emulator' FSMO role in Active Directory?

    Answer: Acts as the authoritative time source and handles password changes and account lockouts

    The PDC Emulator is the authoritative time source for the domain, processes password changes in near-real-time, and is the first DC checked during account lockout processing.

  2. When implementing LDAP in a CIAM solution, what is the primary security concern with using simple bind authentication?

    Answer: Credentials are transmitted in cleartext unless TLS is also enforced

    Simple bind sends the DN and password in plaintext over the network, making it vulnerable to credential interception unless the connection is protected by TLS/LDAPS.

  3. What is a 'Directory Information Tree' (DIT)?

    Answer: The hierarchical structure of entries stored in an LDAP directory

    The DIT is the tree-shaped logical structure that organizes all directory entries according to their distinguished names in a parent-child hierarchy.

  4. Which Azure AD feature allows administrators to control which users and groups can access a specific enterprise application?

    Answer: User assignment required

    Enabling 'User assignment required' on an enterprise application restricts access so only explicitly assigned users or groups can authenticate to that app.

  5. What does 'operational attribute' mean in LDAP terminology?

    Answer: An attribute maintained by the server (e.g., createTimestamp) not returned unless explicitly requested

    Operational attributes like createTimestamp, modifyTimestamp, and entryUUID are maintained automatically by the server and are not included in search results unless specifically requested with '+'.

  6. In Active Directory, what is the difference between a 'universal' group and a 'global' group?

    Answer: Universal groups can contain members from any domain in the forest; global groups can only contain members from their own domain

    Universal groups can include members from any domain in the forest and are replicated to the Global Catalog, while global groups are limited to members from their own domain.

  7. What is the purpose of the 'entryTTL' operational attribute in an LDAP directory?

    Answer: Specifies the remaining time-to-live for a dynamically created directory entry

    entryTTL is used with dynamic entries (RFC 2589) to specify how many seconds remain before the entry expires and is automatically deleted by the server.