โ† All CIAM Flashcard Decks

Security and Risk Management Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Risk Management flashcards as text
  1. Which risk treatment option involves purchasing cyber liability insurance to cover potential losses from an identity breach?

    Answer: Risk transference

    Risk transference shifts the financial impact of a risk to a third party, such as an insurance provider.

  2. A CIAM system detects 500 failed login attempts from a single IP in one minute. Which control is BEST suited to address this threat?

    Answer: Rate limiting and IP-based throttling

    Rate limiting and IP-based throttling directly counters brute-force and credential-stuffing attacks at the network layer.

  3. What is the PRIMARY purpose of a Risk Register in an IAM security program?

    Answer: To document, prioritize, and monitor identified risks

    A Risk Register is a central repository for recording, assessing, prioritizing, and tracking risks and their treatment plans.

  4. An organization's CIAM platform stores PII for millions of customers. Which regulation primarily governs data breach notification requirements in the United States at the federal level for financial institutions?

    Answer: GLBA Safeguards Rule

    The GLBA Safeguards Rule (amended 2023) requires financial institutions to notify the FTC within 30 days of a breach affecting 500+ customers.

  5. What does 'inherent risk' mean in the context of IAM security assessments?

    Answer: The risk level before any mitigating controls are in place

    Inherent risk is the raw or untreated risk exposure that exists before any security controls are implemented.

  6. Which attack targets CIAM systems by using large sets of previously stolen username/password pairs to gain unauthorized access?

    Answer: Credential stuffing

    Credential stuffing automates the testing of breached credential lists against login endpoints to exploit password reuse.

  7. When conducting a Business Impact Analysis (BIA) for a CIAM system, what is the MOST critical output?

    Answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for the identity service

    The BIA's most critical output is defining RTO and RPO, which drives recovery planning for the identity service.