← All CIAM Flashcard Decks

Security and Risk Management Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security and Risk Management flashcards as text
  1. Which security principle ensures that a user's access rights are limited to only what is necessary to perform their job function?

    Answer: Least privilege

    Least privilege restricts user access rights to the minimum permissions required for their specific role or task.

  2. A CIAM administrator discovers that a third-party identity provider (IdP) has suffered a breach. What is the FIRST step to take?

    Answer: Revoke or invalidate all active sessions and tokens issued by that IdP

    Revoking active sessions and tokens from the compromised IdP immediately stops attackers from leveraging stolen credentials.

  3. What is the significance of a 'threat actor' in risk management for CIAM systems?

    Answer: An entity or group with the intent and capability to exploit vulnerabilities

    A threat actor is any individual, group, or organization with the motivation and capability to attack a system.

  4. Which framework provides a structured approach to categorizing information systems and selecting security controls based on impact levels?

    Answer: NIST SP 800-53

    NIST SP 800-53 provides a catalog of security and privacy controls organized around system impact levels (Low, Moderate, High).

  5. An organization wants to verify that its CIAM security controls are working as designed. Which activity BEST accomplishes this?

    Answer: Conducting a security control assessment or audit

    A security control assessment validates that implemented controls are operating effectively and meeting their intended objectives.

  6. What is 'attack surface' in the context of a CIAM platform?

    Answer: The sum of all points where unauthorized users can attempt to enter or extract data

    The attack surface encompasses all the exposed endpoints, APIs, interfaces, and entry points that could be exploited by an attacker.

  7. Which type of risk assessment uses numerical values and statistical models to quantify potential losses?

    Answer: Quantitative risk assessment

    Quantitative risk assessments use financial metrics like Annual Loss Expectancy (ALE) to express risk in monetary terms.