← All CIAM Flashcard Decks

Governance and Compliance Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Governance and Compliance flashcards as text
  1. Under GDPR, what is the maximum fine for a Tier 2 violation as a percentage of global annual turnover?

    Answer: 4%

    GDPR Tier 2 violations (the most serious) carry fines up to 4% of global annual turnover or €20 million, whichever is higher.

  2. Which IAM governance framework artifact maps business roles to IT entitlements?

    Answer: Role catalog

    A role catalog defines and maps business roles to their associated IT entitlements, forming the foundation of role-based access control governance.

  3. A SOC 2 Type II report differs from SOC 2 Type I primarily in that it:

    Answer: Evaluates controls over a period of time rather than a point in time

    SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (typically 6–12 months), while Type I assesses design at a single point in time.

  4. Which principle requires that access rights be reviewed and removed when no longer needed for a job function?

    Answer: Least privilege

    Least privilege mandates that users retain only the minimum access necessary for their current role, requiring revocation when access is no longer justified.

  5. Under HIPAA, which entity must sign a Business Associate Agreement (BAA) with a covered entity?

    Answer: Vendors who handle protected health information on behalf of the covered entity

    A BAA is required for any business associate that creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity.

  6. An organization discovers that a former employee's SSO account was not deprovisioned for 45 days after termination. Which governance control failure does this best represent?

    Answer: Failed leaver workflow

    A leaver workflow governs the timely revocation of access upon employment termination; failure to execute it left the account active.

  7. Which PCI DSS requirement specifically mandates restricting access to system components and cardholder data to only those individuals whose job requires such access?

    Answer: Requirement 7

    PCI DSS Requirement 7 requires limiting access to system components and cardholder data to those with a legitimate business need.