โ† All CIAM Flashcard Decks

Foundational Frameworks Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Foundational Frameworks flashcards as text
  1. Which NIST publication provides the primary guidance for digital identity risk management and defines assurance levels?

    Answer: NIST SP 800-63

    NIST SP 800-63 defines Identity Assurance Level (IAL), Authenticator Assurance Level (AAL), and Federation Assurance Level (FAL).

  2. Under the Zero Trust Architecture framework, which principle states that no user or device should be inherently trusted regardless of network location?

    Answer: Never trust, always verify

    The 'never trust, always verify' principle is the foundational tenet of Zero Trust, requiring continuous authentication and authorization.

  3. In the OAuth 2.0 framework, what is the role of the Authorization Server?

    Answer: Issues access tokens after authenticating the resource owner

    The Authorization Server authenticates the resource owner and issues access tokens to the client after obtaining authorization.

  4. Which identity governance concept ensures that a user's access rights are reviewed and confirmed by an authoritative party at regular intervals?

    Answer: Access certification

    Access certification (access review/recertification) is the periodic process of validating that users still require their current access rights.

  5. The SCIM (System for Cross-domain Identity Management) protocol is primarily used for which purpose?

    Answer: Automating user provisioning and deprovisioning across systems

    SCIM provides a standardized REST-based API for automating the exchange of user identity information between identity domains.

  6. Which framework uses a maturity model with five levels (Initial, Managed, Defined, Quantitatively Managed, Optimizing) applicable to IAM process improvement?

    Answer: CMMI

    CMMI (Capability Maturity Model Integration) defines five process maturity levels used to assess and improve organizational processes including IAM.

  7. In a federated identity model, what is an Identity Provider (IdP) responsible for?

    Answer: Authenticating users and asserting their identity to service providers

    The IdP authenticates users and issues identity assertions (e.g., SAML assertions or OIDC tokens) that relying parties trust.