โ† All CIAM Flashcard Decks

Privileged Access Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privileged Access flashcards as text
  1. Which best practice addresses the risk of an administrator using a single account for both privileged and non-privileged tasks?

    Answer: Requiring separate admin and standard user accounts

    Maintaining separate accounts for privileged and day-to-day activities limits the exposure of admin credentials during routine browsing or email.

  2. What is the main risk of using shared privileged accounts (e.g., a single 'root' account used by multiple administrators)?

    Answer: Inability to attribute actions to a specific individual

    Shared accounts break accountability because audit logs cannot determine which individual performed a privileged action.

  3. A cloud administrator is granted temporary elevated access via an automated workflow that expires after 4 hours. This is an example of:

    Answer: Just-in-time (JIT) privileged access

    Just-in-time privileged access grants elevated permissions on-demand for a limited time window and revokes them automatically.

  4. Which control helps detect a compromised privileged account by establishing a baseline of normal behavior and alerting on deviations?

    Answer: User and Entity Behavior Analytics (UEBA)

    UEBA uses machine learning to model normal privileged user behavior and flags anomalous activities that may indicate compromise.

  5. In a PAM deployment, what is the purpose of 'application-to-application password management' (AAPM)?

    Answer: To eliminate hard-coded credentials in scripts and applications by fetching secrets at runtime

    AAPM removes hard-coded or embedded credentials from applications by having them retrieve secrets dynamically from a vault.

  6. Which principle states that a privileged user should only be able to access systems relevant to their specific administrative function?

    Answer: Need-to-know

    Need-to-know restricts access to information or systems based on whether access is necessary for the user's defined job function.

  7. An organization discovers that a terminated contractor's service account is still active and has domain admin rights. Which process failure does this represent?

    Answer: Failure of offboarding/deprovisioning procedures

    Proper offboarding must include immediate deprovisioning of all accounts, especially privileged ones, to prevent unauthorized access after termination.