โ† All CIAM Flashcard Decks

Foundational Frameworks Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Foundational Frameworks flashcards as text
  1. Which design pattern in IAM architecture centralizes policy decision-making while distributing policy enforcement across multiple applications?

    Answer: Externalized authorization

    Externalized authorization separates the PDP from applications so that access policy is managed centrally while each app enforces decisions via a PEP.

  2. According to GDPR and privacy-by-design principles, which IAM practice directly supports the 'data minimization' principle?

    Answer: Provisioning only the attributes required for a specific transaction

    Data minimization requires that only the minimum necessary personal data be collected and shared, which in IAM means releasing only required attributes during provisioning or federation.

  3. Which standard protocol enables a client to obtain user identity information from an authorization server using a RESTful API after obtaining an access token?

    Answer: OpenID Connect (OIDC)

    OpenID Connect adds an identity layer on top of OAuth 2.0, allowing clients to retrieve user profile information via the UserInfo endpoint.

  4. A SOC 2 Type II audit report for an identity provider is most useful for evaluating which aspect of the IdP?

    Answer: The effectiveness of the IdP's security controls over a period of time

    A SOC 2 Type II report attests to the design and operating effectiveness of security, availability, and confidentiality controls over a defined review period.

  5. Which identity framework component provides a standardized way to express and exchange risk scoring information about authentication events across systems?

    Answer: Shared Signals Framework (SSF) / CAEP

    The Shared Signals Framework (SSF) and Continuous Access Evaluation Profile (CAEP) enable real-time sharing of security events (e.g., session revocation, risk level changes) between IdPs and RPs.

  6. In IAM architecture, a 'canonical identity' refers to which concept?

    Answer: The authoritative master record of a user's identity attributes used to synchronize other systems

    A canonical identity is the golden record maintained in an authoritative source (like an HR system) from which all other identity representations are derived.

  7. Which IAM architectural decision addresses the risk of a single identity provider outage affecting access to all dependent applications?

    Answer: Deploying a high-availability IdP cluster with failover capabilities

    High-availability IdP deployment with clustering and geographic failover ensures authentication services remain available even if individual nodes fail.