← All CIAM Flashcard Decks

Privileged Access Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Privileged Access flashcards as text
  1. A service account has been granted local administrator rights on 500 servers with the same password. Which PAM risk does this represent?

    Answer: Lateral movement risk

    Shared static credentials across many systems allow an attacker who compromises one system to move laterally across the entire environment.

  2. Which IAM concept ensures that privileged access rights are removed when an employee changes roles or leaves the organization?

    Answer: Access recertification

    Access recertification (also called access review) is the periodic process of validating and revoking unnecessary or outdated access rights.

  3. What is 'privilege creep' in identity and access management?

    Answer: The gradual accumulation of access rights beyond what a user's current role requires

    Privilege creep occurs when users accumulate permissions over time through role changes without prior access being removed.

  4. Which component of a PAM architecture acts as a proxy to enforce session control and policy without exposing target system credentials to end users?

    Answer: Privileged access gateway

    A privileged access gateway sits between the admin and the target system, injecting credentials and enforcing policy transparently.

  5. Under the NIST SP 800-53 framework, which control family primarily addresses privileged account management?

    Answer: Access Control (AC)

    The Access Control family, particularly AC-2 and AC-6, governs privileged account management and least-privilege enforcement.

  6. An attacker exploits a Kerberos vulnerability to forge tickets granting domain admin access. What is this attack called?

    Answer: Golden ticket attack

    A golden ticket attack forges Kerberos TGTs using the krbtgt account hash, granting persistent domain admin access.

  7. Which privileged access control method limits what commands a sudo user can run by defining rules in a configuration file?

    Answer: Sudoers file

    The /etc/sudoers file defines granular rules specifying which users can run which commands with elevated privileges on Unix/Linux systems.