Governance and Compliance Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Governance and Compliance flashcards as text
Which IAM audit technique uses automated comparison of current user access rights against an approved entitlement baseline?
Answer: Variance analysis
Variance analysis compares actual entitlements to an approved baseline, flagging differences that may indicate unauthorized or drifted access.
Under NIST SP 800-53, which control family most directly governs access control policies and procedures?
Answer: AC – Access Control
The AC (Access Control) family in NIST SP 800-53 contains controls for account management, access enforcement, and least privilege.
A compliance auditor asks for evidence that privileged access is reviewed quarterly. Which IAM artifact best satisfies this request?
Answer: Completed access certification reports with timestamps
Completed access certification reports with timestamps demonstrate that privileged accounts were reviewed at the required frequency.
In IAM governance, 'toxic combinations' refer to:
Answer: Combinations of permissions that violate segregation of duties
Toxic combinations are pairs or sets of entitlements that, when held by the same user, violate segregation of duties and create fraud or error risk.
Which regulation requires US federal agencies to use FIPS 201-compliant credentials for logical access to IT systems?
Answer: FISMA
FISMA (Federal Information Security Modernization Act) mandates that federal agencies comply with NIST standards, including FIPS 201 for Personal Identity Verification.
An access review finds that a developer has both 'deploy to production' and 'approve production changes' permissions. Which governance concept does remediating this violation address?
Answer: Segregation of duties
Segregation of duties prevents a single person from controlling all steps of a critical process; separating deploy and approval rights enforces this principle.
Under CCPA, what right allows California consumers to request that a business delete personal information collected about them?
Answer: Right to deletion
The CCPA Right to Deletion allows California consumers to request that businesses delete personal information collected, subject to certain exceptions.