โ† All CIAM Flashcard Decks

Security and Risk Management Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Risk Management flashcards as text
  1. Which OWASP category directly addresses broken or misconfigured access control mechanisms in web-based CIAM applications?

    Answer: Broken Access Control

    Broken Access Control (OWASP A01:2021) covers failures where users can act outside their intended permissions.

  2. A CIAM risk assessment reveals that a specific threat has a high likelihood but a low impact. How should this risk TYPICALLY be prioritized?

    Answer: Monitored and assigned a medium priority

    High likelihood combined with low impact generally places a risk in the medium priority range, requiring monitoring but not emergency response.

  3. Which authentication security control directly reduces the risk of credential theft by ensuring passwords are never stored in plaintext?

    Answer: Password hashing with salt using bcrypt or Argon2

    Salted hashing with algorithms like bcrypt or Argon2 ensures that even if the database is breached, plaintext passwords cannot be recovered.

  4. What is the purpose of a 'tabletop exercise' in the context of CIAM incident response planning?

    Answer: To simulate a security incident scenario and walk through response procedures verbally

    A tabletop exercise is a discussion-based simulation where participants talk through their response to a hypothetical incident without real-world execution.

  5. In zero-trust architecture applied to CIAM, which statement BEST describes the core security assumption?

    Answer: No user or device is trusted by default, and every access request must be continuously verified

    Zero trust operates on the principle of 'never trust, always verify,' requiring continuous validation of every access request regardless of network location.

  6. Which metric measures the average time it takes an organization to detect a security breach within its CIAM environment?

    Answer: Mean Time to Detect (MTTD)

    MTTD (Mean Time to Detect) measures the average elapsed time between a breach occurring and the organization identifying it.

  7. A CIAM vendor is granted access to production user data for troubleshooting. Which control BEST manages the security risk of this third-party access?

    Answer: Implementing just-in-time (JIT) privileged access with session recording and time-limited permissions

    JIT privileged access grants temporary, audited access only when needed, minimizing the window of exposure from third-party vendors.