← All CIAM Flashcard Decks

Governance and Compliance Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Governance and Compliance flashcards as text
  1. Which IAM audit technique uses automated comparison of current user access rights against an approved entitlement baseline?

    Answer: Variance analysis

    Variance analysis compares actual entitlements to an approved baseline, flagging differences that may indicate unauthorized or drifted access.

  2. Under NIST SP 800-53, which control family most directly governs access control policies and procedures?

    Answer: AC – Access Control

    The AC (Access Control) family in NIST SP 800-53 contains controls for account management, access enforcement, and least privilege.

  3. A compliance auditor asks for evidence that privileged access is reviewed quarterly. Which IAM artifact best satisfies this request?

    Answer: Completed access certification reports with timestamps

    Completed access certification reports with timestamps demonstrate that privileged accounts were reviewed at the required frequency.

  4. In IAM governance, 'toxic combinations' refer to:

    Answer: Combinations of permissions that violate segregation of duties

    Toxic combinations are pairs or sets of entitlements that, when held by the same user, violate segregation of duties and create fraud or error risk.

  5. Which regulation requires US federal agencies to use FIPS 201-compliant credentials for logical access to IT systems?

    Answer: FISMA

    FISMA (Federal Information Security Modernization Act) mandates that federal agencies comply with NIST standards, including FIPS 201 for Personal Identity Verification.

  6. An access review finds that a developer has both 'deploy to production' and 'approve production changes' permissions. Which governance concept does remediating this violation address?

    Answer: Segregation of duties

    Segregation of duties prevents a single person from controlling all steps of a critical process; separating deploy and approval rights enforces this principle.

  7. Under CCPA, what right allows California consumers to request that a business delete personal information collected about them?

    Answer: Right to deletion

    The CCPA Right to Deletion allows California consumers to request that businesses delete personal information collected, subject to certain exceptions.