Foundational Frameworks Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Foundational Frameworks flashcards as text
Which component of the NIST Cybersecurity Framework (CSF) specifically addresses the ability to detect the occurrence of a cybersecurity event?
Answer: Detect
The Detect function in the NIST CSF defines activities for timely discovery of cybersecurity events, including continuous monitoring and anomaly detection.
When implementing an IAM solution, which process maps existing system permissions and entitlements back to defined business roles to inform role design?
Answer: Role engineering (bottom-up)
Bottom-up role engineering mines existing access data to discover patterns and build roles from real-world entitlement assignments.
In the context of IAM frameworks, which term describes the complete set of access rights, permissions, and privileges held by a specific user across all systems?
Answer: Entitlement inventory
An entitlement inventory catalogs all access rights assigned to a user across every application, system, and resource in the environment.
Which trust framework component establishes the rules, obligations, and liability between identity providers and relying parties in a federation?
Answer: Federation agreement (trust agreement)
A federation agreement (or trust agreement) is the legal and technical contract that governs how identity assertions are trusted across organizational boundaries.
The principle of 'context-aware authentication' requires that authentication strength be determined by which factor?
Answer: Risk signals such as device posture, location, and behavior
Context-aware (risk-based) authentication dynamically adjusts the required assurance level based on environmental risk signals at the time of login.
Which identity lifecycle stage is most critical for preventing 'ghost accounts' that could be exploited after an employee departure?
Answer: Deprovisioning
Deprovisioning (offboarding) must promptly disable or delete accounts when users leave to prevent unauthorized post-departure access.
In an IAM maturity model, an organization at the 'Managed' level is best characterized by which capability?
Answer: Defined and documented IAM processes applied consistently across the enterprise
A Managed (or Defined) level organization has standardized, documented IAM processes that are consistently followed enterprise-wide.