CIAM β Certified Identity and Access Manager β Questions and Answers
Question 1: A healthcare organization must ensure that only authorized workforce members access ePHI based on their job function. Which HIPAA concept does this describe?
- Break-glass access procedure
- De-identification of PHI
- Role-based access control
- Minimum necessary standard (Correct answer)
Correct answer: Minimum necessary standard
The HIPAA Minimum Necessary standard requires covered entities to limit access to ePHI to only what is needed for the workforce member's job function.
Question 2: A CIAM administrator discovers that a third-party identity provider (IdP) has suffered a breach. What is the FIRST step to take?
- Conduct a penetration test
- Notify all end users immediately
- Revoke or invalidate all active sessions and tokens issued by that IdP (Correct answer)
- Shut down the entire CIAM platform
Correct answer: Revoke or invalidate all active sessions and tokens issued by that IdP
Revoking active sessions and tokens from the compromised IdP immediately stops attackers from leveraging stolen credentials.
Question 3: Which OAuth 2.0 flow is recommended for server-to-server authentication without user interaction?
- Implicit Flow
- Authorization Code Flow
- Client Credentials Flow (Correct answer)
- Device Authorization Flow
Correct answer: Client Credentials Flow
The Client Credentials Flow is designed for machine-to-machine authentication where no user is present and only client credentials are used.
Question 4: What is the main purpose of Role-Based Access Control (RBAC) in an IAM framework?
- To require additional passwords for different levels of access
- To give users unlimited access to all systems
- To control the access of individual users based on their role within the organization (Correct answer)
- To authenticate users using biometric data
Correct answer: To control the access of individual users based on their role within the organization
Role-Based Access Control (RBAC) is a method of restricting system access based on the roles of individual users within an organization. It ensures that users are granted only the necessary permissions to perform their job functions, simplifying access management and enhancing security.
Question 5: A CIAM vendor is granted access to production user data for troubleshooting. Which control BEST manages the security risk of this third-party access?
- Disabling logging for the vendor's session to improve performance
- Implementing just-in-time (JIT) privileged access with session recording and time-limited permissions (Correct answer)
- Allowing the vendor to self-manage their own account
- Providing the vendor with permanent admin credentials
Correct answer: Implementing just-in-time (JIT) privileged access with session recording and time-limited permissions
JIT privileged access grants temporary, audited access only when needed, minimizing the window of exposure from third-party vendors.
Question 6: The principle of 'context-aware authentication' requires that authentication strength be determined by which factor?
- The user's seniority level within the organization
- The classification level of the directory server being queried
- The number of characters in the user's password
- Risk signals such as device posture, location, and behavior (Correct answer)
Correct answer: Risk signals such as device posture, location, and behavior
Context-aware (risk-based) authentication dynamically adjusts the required assurance level based on environmental risk signals at the time of login.
Question 7: What is the purpose of access certification campaigns?
- Certifying IAM administrators through formal examinations
- Issuing digital identity certificates to new employees
- Testing IAM system performance under peak load conditions
- Periodically verifying that users retain only appropriate access rights by having managers review and approve (Correct answer)
Correct answer: Periodically verifying that users retain only appropriate access rights by having managers review and approve
Access certification campaigns periodically require managers or system owners to review and confirm that each user's access rights remain appropriate for their current role.
Question 8: Which security concept defines the maximum acceptable downtime for a CIAM authentication service before business operations are critically impacted?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Service Level Agreement (SLA)
- Mean Time to Repair (MTTR)
Correct answer: Recovery Time Objective (RTO)
RTO defines the maximum tolerable length of time a system can be offline before the impact becomes unacceptable to the business.
Question 9: The Chinese Wall Model is primarily designed to prevent:
- Insider threats from disgruntled employees
- Privilege escalation attacks
- Unauthorized data deletion
- Conflicts of interest between competing organizations (Correct answer)
Correct answer: Conflicts of interest between competing organizations
The Chinese Wall (Brewer-Nash) Model prevents consultants from accessing data from competing companies by dynamically restricting access based on prior accesses.
Question 10: What is the purpose of a 'tabletop exercise' in the context of CIAM incident response planning?
- To simulate a security incident scenario and walk through response procedures verbally (Correct answer)
- To physically test network failover hardware
- To review and update user access permissions
- To perform live penetration testing on the CIAM platform
Correct answer: To simulate a security incident scenario and walk through response procedures verbally
A tabletop exercise is a discussion-based simulation where participants talk through their response to a hypothetical incident without real-world execution.
Question 11: In a directory service context, what is 'federation' with an external IdP primarily used for?
- Synchronizing directory objects between two domains
- Replicating schema changes across forests
- Providing offline access to directory resources
- Allowing users from an external organization to authenticate using their own identity provider (Correct answer)
Correct answer: Allowing users from an external organization to authenticate using their own identity provider
Directory federation enables cross-organizational single sign-on by establishing trust so that an external IdP can assert authenticated user identities to local services.
Question 12: Which risk-based authentication signal is most commonly used to detect an anomalous login attempt that warrants step-up verification?
- The user's password length
- The time since the user last changed their password
- IP geolocation and device fingerprint changes (Correct answer)
- The user's job title from HR system
Correct answer: IP geolocation and device fingerprint changes
Risk-based authentication engines primarily evaluate contextual signals like IP geolocation changes, unfamiliar devices, and unusual access patterns to flag suspicious logins.
Question 13: A CIAM platform uses JSON Web Tokens (JWTs) for session management. Which vulnerability arises when JWT signature verification is bypassed by setting the algorithm to 'none'?
- Algorithm confusion attack (Correct answer)
- Cross-site request forgery
- Session fixation
- Token replay attack
Correct answer: Algorithm confusion attack
The 'alg:none' algorithm confusion attack allows attackers to forge tokens by stripping signature validation entirely.
Question 14: The GDPR principle of 'data minimization' most directly influences which IAM practice?
- Password complexity requirements
- Least privilege access provisioning (Correct answer)
- Identity federation across domains
- Single sign-on implementation
Correct answer: Least privilege access provisioning
Data minimization aligns with least privilege by ensuring users only access the minimum data necessary for their role.
Question 15: In a PAM deployment, what is the purpose of 'application-to-application password management' (AAPM)?
- To rotate end-user passwords automatically
- To eliminate hard-coded credentials in scripts and applications by fetching secrets at runtime (Correct answer)
- To enforce password complexity for service accounts
- To allow apps to use SSO for privileged access
Correct answer: To eliminate hard-coded credentials in scripts and applications by fetching secrets at runtime
AAPM removes hard-coded or embedded credentials from applications by having them retrieve secrets dynamically from a vault.
Question 16: Which best practice addresses the risk of an administrator using a single account for both privileged and non-privileged tasks?
- Implementing MFA
- Using a VPN for all admin sessions
- Requiring separate admin and standard user accounts (Correct answer)
- Enforcing password complexity
Correct answer: Requiring separate admin and standard user accounts
Maintaining separate accounts for privileged and day-to-day activities limits the exposure of admin credentials during routine browsing or email.
Question 17: Which component of a PAM architecture acts as a proxy to enforce session control and policy without exposing target system credentials to end users?
- Identity broker
- Token service
- Privileged access gateway (Correct answer)
- Directory server
Correct answer: Privileged access gateway
A privileged access gateway sits between the admin and the target system, injecting credentials and enforcing policy transparently.
Question 18: What is the PRIMARY risk of allowing users to self-register without any verification in a CIAM system?
- Increased server load from too many accounts
- Slower authentication response times
- Account enumeration and fake account creation enabling fraud (Correct answer)
- Higher storage costs for user data
Correct answer: Account enumeration and fake account creation enabling fraud
Unverified self-registration enables fraudsters to create fake accounts for fraud, spam, or credential-stuffing cover.
Question 19: How does identity governance differ from identity administration?
- Governance uses AI exclusively; administration uses rule-based automation
- Governance manages cloud identities only; administration manages on-premises identities
- Governance is performed by end users; administration is performed by IT
- Governance focuses on policy, risk, and compliance; administration focuses on provisioning and technical tasks (Correct answer)
Correct answer: Governance focuses on policy, risk, and compliance; administration focuses on provisioning and technical tasks
Identity governance encompasses the business controls, risk management, and compliance oversight of identities, while identity administration handles the technical provisioning and lifecycle operations.
Question 20: What is 'continuous monitoring' in IAM?
- Continuously deploying software updates to IAM systems
- Requiring users to continuously change their passwords
- Providing 24/7 IT help desk support to users
- Ongoing real-time analysis of security controls and user activity to detect threats and anomalies (Correct answer)
Correct answer: Ongoing real-time analysis of security controls and user activity to detect threats and anomalies
Continuous monitoring provides persistent, real-time visibility into access activity and security control effectiveness, enabling rapid detection of anomalies and policy violations.
Question 21: Which SAML binding transmits messages as base64-encoded URL query parameters?
- Artifact Binding
- SOAP Binding
- HTTP Redirect Binding (Correct answer)
- HTTP POST Binding
Correct answer: HTTP Redirect Binding
HTTP Redirect Binding base64-encodes SAML messages and passes them as URL query parameters in an HTTP redirect, used primarily for smaller authentication request messages.
Question 22: In the Biba Integrity Model, the 'no write up' property means that a subject:
- Cannot read objects at a lower integrity level
- Cannot execute programs at any integrity level
- Cannot write to objects at a higher integrity level (Correct answer)
- Cannot modify its own security label
Correct answer: Cannot write to objects at a higher integrity level
In Biba, subjects cannot write to objects at higher integrity levels to prevent corrupting trusted data with less-trusted data.
Question 23: When a user is rehired after a gap in employment, what is the recommended practice for their identity account?
- Use the archived account but require a full access re-certification before activation (Correct answer)
- Restore the old account with all previous entitlements intact
- Create a new account with fresh provisioning based on the new role
- Allow the user to self-service recover their old account credentials
Correct answer: Use the archived account but require a full access re-certification before activation
Restoring an archived account with a re-certification step ensures the rehired employee gets appropriate access for their new role without inheriting stale entitlements.
Question 24: Which of the following IAM tools is designed to manage privileged access to sensitive systems and resources?
- Virtual Private Network (VPN)
- Privileged Access Management (PAM) (Correct answer)
- Identity Federation
- Access Control Lists (ACLs)
Correct answer: Privileged Access Management (PAM)
PAM tools are designed to control and monitor access to critical systems by managing and securing privileged accounts. They help ensure that only authorized users have elevated access to sensitive resources.
Question 25: An IAM team wants to correlate identity events with security alerts in real time. Which tool integration is most relevant?
- Integrating the IAM system with a SIEM platform (Correct answer)
- Connecting the IAM system to a CDN
- Attaching IAM logs to a CRM system
- Linking IAM to a load balancer
Correct answer: Integrating the IAM system with a SIEM platform
Integrating IAM with a SIEM allows security teams to correlate identity events (logins, permission changes) with broader security telemetry.
Question 26: A regulated bank must ensure that a loan officer cannot both initiate and approve the same transaction. Which IAM control enforces this?
- Time-based access restriction
- Multi-factor authentication
- Privileged identity management
- Segregation of duties (SoD) (Correct answer)
Correct answer: Segregation of duties (SoD)
Segregation of Duties (SoD) prevents a single individual from having conflicting roles, such as both initiating and approving financial transactions.
Question 27: Which token format is most commonly used in modern OAuth 2.0 and OpenID Connect implementations?
- JSON Web Token (JWT) (Correct answer)
- X.509 certificate
- SAML assertion
- Kerberos ticket
Correct answer: JSON Web Token (JWT)
JSON Web Tokens (JWTs) are widely used as access tokens and ID tokens in OAuth 2.0 and OpenID Connect due to their compact, self-contained structure.
Question 28: When implementing ABAC, a policy stating 'Allow access if user.clearance >= resource.classification AND user.department == resource.owner_department' is an example of:
- An ABAC policy rule combining subject and resource attributes (Correct answer)
- A capability token
- An ACL entry
- A Mandatory Access Control label comparison
Correct answer: An ABAC policy rule combining subject and resource attributes
This is a classic ABAC policy rule that combines subject attributes (clearance, department) with resource attributes (classification, owner department) to make an access decision.
Question 29: What is a 'Directory Information Tree' (DIT)?
- The hierarchical structure of entries stored in an LDAP directory (Correct answer)
- A schema extension for storing binary data
- A log file recording all directory changes for auditing
- A redundancy model for distributing directory data across servers
Correct answer: The hierarchical structure of entries stored in an LDAP directory
The DIT is the tree-shaped logical structure that organizes all directory entries according to their distinguished names in a parent-child hierarchy.
Question 30: What is the significance of 'time-stamping' in IAM audit logs?
- It establishes the sequence and timing of events, which is critical for forensic investigation and compliance (Correct answer)
- It manages password expiration schedules
- It controls when access certification campaigns are triggered
- It determines user session timeout intervals
Correct answer: It establishes the sequence and timing of events, which is critical for forensic investigation and compliance
Accurate timestamps in audit logs establish the precise sequence of events, which is essential for reconstructing incidents, proving compliance, and correlating events across systems.
Question 31: What does 'operational attribute' mean in LDAP terminology?
- An attribute maintained by the server (e.g., createTimestamp) not returned unless explicitly requested (Correct answer)
- An attribute that triggers server-side business logic when modified
- An attribute required by all object classes in the schema
- An attribute used to link two entries through a referential integrity constraint
Correct answer: An attribute maintained by the server (e.g., createTimestamp) not returned unless explicitly requested
Operational attributes like createTimestamp, modifyTimestamp, and entryUUID are maintained automatically by the server and are not included in search results unless specifically requested with '+'.
Question 32: Under SOC 2 Trust Service Criteria, which criteria category covers logical and physical access controls?
- Availability (A)
- Change Management (CC8)
- Logical and Physical Access Controls (CC6) (Correct answer)
- Confidentiality (C)
Correct answer: Logical and Physical Access Controls (CC6)
SOC 2 Common Criteria CC6 specifically addresses logical and physical access controls as part of the Common Criteria related to logical and physical access.
Question 33: Under HIPAA, which entity must sign a Business Associate Agreement (BAA) with a covered entity?
- Vendors located outside the United States
- Vendors providing cloud infrastructure only
- Vendors who handle protected health information on behalf of the covered entity (Correct answer)
- Any vendor the covered entity pays
Correct answer: Vendors who handle protected health information on behalf of the covered entity
A BAA is required for any business associate that creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity.
Question 34: What does a formal access rights review typically assess?
- Whether current user permissions align with job responsibilities and the least privilege principle (Correct answer)
- Network performance and bandwidth utilization
- Password complexity and strength across all accounts
- Software license compliance across the organization
Correct answer: Whether current user permissions align with job responsibilities and the least privilege principle
Access rights reviews compare users' current permissions against their actual job role requirements, identifying excessive, unused, or otherwise inappropriate access rights.
Question 35: In SAML, what is an 'assertion'?
- A public key certificate issued by a CA
- A password hash used for authentication
- A firewall rule granting access
- An XML statement conveying information about a subject's identity and attributes (Correct answer)
Correct answer: An XML statement conveying information about a subject's identity and attributes
A SAML assertion is an XML-based statement issued by an Identity Provider that conveys identity, attribute, and authorization decision information about a subject.
Question 36: What is the primary function of Single Sign-On (SSO)?
- To allow multiple systems to authenticate users using one central directory (Correct answer)
- To ensure users can log in with a username and password only once
- To allow users to authenticate using a biometric factor only
- To enable users to sign in to different systems with separate credentials
Correct answer: To allow multiple systems to authenticate users using one central directory
Single Sign-On (SSO) streamlines the authentication process by allowing users to log in once with a single set of credentials to access multiple independent software systems. This centralizes user authentication, improving convenience and security by reducing the number of passwords users need to manage.
Question 37: Which compliance framework introduced the concept of 'segregation of duties' as a key control for preventing fraud in financial systems?
- ISO 27001
- Sarbanes-Oxley Act (SOX) (Correct answer)
- FISMA
- NIST SP 800-53
Correct answer: Sarbanes-Oxley Act (SOX)
SOX heavily emphasizes segregation of duties as an internal control to prevent a single individual from controlling all aspects of a financial transaction.
Question 38: What is the purpose of a recertification campaign in IAM?
- Periodically requiring managers to review and reconfirm that team members' access rights remain appropriate (Correct answer)
- Renewing SSL/TLS certificates used in the IAM infrastructure
- Restarting IAM services to apply configuration changes
- Recertifying IAM administrators' professional credentials
Correct answer: Periodically requiring managers to review and reconfirm that team members' access rights remain appropriate
Recertification campaigns mandate that access rights be actively reconfirmed on a scheduled basis, rather than remaining in place indefinitely once granted.
Question 39: Under GDPR, what is the maximum fine for a Tier 2 violation as a percentage of global annual turnover?
- 2%
- 4% (Correct answer)
- 6%
- 10%
Correct answer: 4%
GDPR Tier 2 violations (the most serious) carry fines up to 4% of global annual turnover or β¬20 million, whichever is higher.
Question 40: What is 'directory virtualization' in an enterprise IAM architecture?
- Replicating directory data to a cloud provider for geographic redundancy
- Creating virtual organizational units that span multiple AD forests
- Running multiple directory services on a single physical server using hypervisors
- A layer that presents a unified LDAP or SCIM interface over multiple heterogeneous identity stores without moving data (Correct answer)
Correct answer: A layer that presents a unified LDAP or SCIM interface over multiple heterogeneous identity stores without moving data
Directory virtualization (e.g., RadiantOne, Oracle OUVD) aggregates multiple disparate identity stores into a single virtual namespace exposed via standard protocols.
Question 41: Which replication topology model does Active Directory Sites and Services use by default to connect domain controllers?
- Ring
- Hub and spoke
- KCC-generated spanning tree (Correct answer)
- Full mesh
Correct answer: KCC-generated spanning tree
The Knowledge Consistency Checker (KCC) automatically generates a bidirectional ring/spanning-tree replication topology between domain controllers within and between sites.
Question 42: An IAM policy exception process should require which of the following before granting a temporary deviation from policy?
- Sign-off from the internal audit team
- Executive sponsorship only
- Proof of compliance with all other policies
- Documented business justification, risk acceptance, and a defined expiration date (Correct answer)
Correct answer: Documented business justification, risk acceptance, and a defined expiration date
A sound exception process requires documented justification, formal risk acceptance by an appropriate owner, and an expiration so exceptions do not become permanent.
Question 43: What is the purpose of 'session binding' in a web SSO deployment?
- Forcing users to re-enter passwords on every page
- Binding SAML assertions to a specific IP address permanently
- Linking the SSO session to a specific browser instance or device to prevent session hijacking (Correct answer)
- Tying user accounts to a single application forever
Correct answer: Linking the SSO session to a specific browser instance or device to prevent session hijacking
Session binding ties an authenticated session to identifiers like a device fingerprint or cookie to reduce the risk of stolen session tokens being used elsewhere.
Question 44: An organization wants to verify that its CIAM security controls are working as designed. Which activity BEST accomplishes this?
- Reviewing vendor documentation
- Redeploying the CIAM platform
- Updating user account passwords
- Conducting a security control assessment or audit (Correct answer)
Correct answer: Conducting a security control assessment or audit
A security control assessment validates that implemented controls are operating effectively and meeting their intended objectives.
Question 45: What does 'log integrity' mean in IAM auditing?
- Compressing log files to reduce storage requirements
- Ensuring audit logs are human-readable and well-formatted
- Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness (Correct answer)
- Synchronizing log timestamps across distributed systems
Correct answer: Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness
Log integrity ensures audit records cannot be altered after creation, typically enforced through cryptographic controls, write-once storage, or tamper-evident log chains.
Question 46: When implementing passwordless authentication using FIDO2/WebAuthn, what is stored on the server side?
- The user's public key and credential ID (Correct answer)
- The user's password hash
- The user's private key
- The user's biometric template
Correct answer: The user's public key and credential ID
In FIDO2/WebAuthn, the server (relying party) stores only the user's public key and credential ID; the private key never leaves the user's authenticator device.
Question 47: In XACML (eXtensible Access Control Markup Language), which component evaluates a policy request and returns an authorization decision?
- Policy Administration Point (PAP)
- Policy Decision Point (PDP) (Correct answer)
- Policy Enforcement Point (PEP)
- Policy Information Point (PIP)
Correct answer: Policy Decision Point (PDP)
The PDP evaluates access requests against applicable policies and returns permit, deny, or indeterminate decisions.
Question 48: Which IAM tool feature automatically removes access rights when an employee changes roles or departments?
- Role explosion detection
- Multifactor enrollment
- Automated deprovisioning / role reconciliation (Correct answer)
- Directory synchronization
Correct answer: Automated deprovisioning / role reconciliation
Automated deprovisioning or role reconciliation ensures access rights are adjusted when HR systems report a role change.
Question 49: An attacker exploits a Kerberos vulnerability to forge tickets granting domain admin access. What is this attack called?
- Pass-the-ticket
- Silver ticket attack
- Golden ticket attack (Correct answer)
- AS-REP roasting
Correct answer: Golden ticket attack
A golden ticket attack forges Kerberos TGTs using the krbtgt account hash, granting persistent domain admin access.
Question 50: What is a federation trust in identity management?
- A certificate revocation list shared between organizations
- A firewall policy governing inter-domain traffic
- A formal agreement between identity domains to accept each other's authentication assertions (Correct answer)
- An encrypted VPN tunnel between servers
Correct answer: A formal agreement between identity domains to accept each other's authentication assertions
A federation trust is a formal relationship between identity domains that establishes mutual acceptance of authentication assertions and defines the terms of that acceptance.
Question 51: What is encryption?
- Compressing files
- Deleting data
- Backing up data
- Converting data into coded format to prevent unauthorized access (Correct answer)
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 52: Which design pattern in IAM architecture centralizes policy decision-making while distributing policy enforcement across multiple applications?
- Federated provisioning hub
- Centralized identity store with local caching
- Externalized authorization (Correct answer)
- Decentralized identity (DID)
Correct answer: Externalized authorization
Externalized authorization separates the PDP from applications so that access policy is managed centrally while each app enforces decisions via a PEP.
Question 53: During remote identity proofing at IAL2, which of the following is typically required?
- An existing federated identity from a social media provider
- Submission of a handwritten notarized affidavit
- In-person biometric capture at a government office
- Automated validation of identity document images and a selfie comparison (Correct answer)
Correct answer: Automated validation of identity document images and a selfie comparison
Remote IAL2 proofing typically requires the applicant to capture images of a government-issued identity document and a selfie, which are then validated and compared using automated systems.
Question 54: Which identity framework component provides a standardized way to express and exchange risk scoring information about authentication events across systems?
- RADIUS accounting records
- LDAP referrals
- X.509 certificate policies
- Shared Signals Framework (SSF) / CAEP (Correct answer)
Correct answer: Shared Signals Framework (SSF) / CAEP
The Shared Signals Framework (SSF) and Continuous Access Evaluation Profile (CAEP) enable real-time sharing of security events (e.g., session revocation, risk level changes) between IdPs and RPs.
Question 55: What is the governance purpose of tracking 'entitlement owner' in an IGA system?
- To establish accountability for approving and reviewing access to that entitlement (Correct answer)
- To calculate the cost of provisioning the entitlement
- To determine which vendor licenses apply to each entitlement
- To map entitlements to physical data center locations
Correct answer: To establish accountability for approving and reviewing access to that entitlement
Entitlement owners are responsible for approving requests and certifying who should have access, creating a clear accountability chain for each permission.
Question 56: What governance mechanism ensures that no single individual can both request AND approve their own access grant?
- Attribute-based access control
- Separation of duties in the approval workflow (Correct answer)
- Role-based access control
- Privileged access management
Correct answer: Separation of duties in the approval workflow
Separation of duties in approval workflows requires a different person to approve access than the one who requested it, preventing self-authorization fraud.
Question 57: What is the key difference between account disablement and account deletion in offboarding workflows?
- Disablement preserves the account and data for audit; deletion removes them (Correct answer)
- Deletion is faster and preferred for all offboarding scenarios
- Disablement is permanent while deletion allows recovery
- Disablement applies to contractors only; deletion applies to employees
Correct answer: Disablement preserves the account and data for audit; deletion removes them
Disabling an account blocks access while retaining the account and associated data for audit trails, litigation holds, and knowledge transfer; deletion is irreversible.
Question 58: NIST SP 800-63A's IAL3 (Identity Assurance Level 3) requires which verification method not mandated at IAL2?
- In-person proofing with a trained operator or Trusted Referee (Correct answer)
- Self-assertion of identity attributes
- Knowledge-based authentication
- Remote document scanning
Correct answer: In-person proofing with a trained operator or Trusted Referee
IAL3 requires in-person proofing (or an equivalent supervised remote session) conducted by a trained operator, providing the highest level of confidence in the identity being established.
Question 59: What is a 'break-glass' account in PAM, and when is it used?
- A read-only monitoring account
- A cloud-federated account used during incidents
- An emergency account with high privileges used only when normal admin access is unavailable (Correct answer)
- A low-privilege account used for testing
Correct answer: An emergency account with high privileges used only when normal admin access is unavailable
Break-glass accounts provide emergency access during system outages or lockouts and are tightly monitored because their use signals an exceptional event.
Question 60: When conducting a Business Impact Analysis (BIA) for a CIAM system, what is the MOST critical output?
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for the identity service (Correct answer)
- The total number of user accounts in the system
- A list of all IAM vendors considered
- A mapping of all application integrations
Correct answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for the identity service
The BIA's most critical output is defining RTO and RPO, which drives recovery planning for the identity service.
Question 61: Which NIST publication provides the primary guidance for digital identity risk management and defines assurance levels?
- NIST SP 800-30
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-63 (Correct answer)
Correct answer: NIST SP 800-63
NIST SP 800-63 defines Identity Assurance Level (IAL), Authenticator Assurance Level (AAL), and Federation Assurance Level (FAL).
Question 62: What is 'privileged user monitoring'?
- Monitoring only non-administrative standard users
- Network-level monitoring of privileged user workstations
- Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts (Correct answer)
- A password complexity monitoring tool for admin accounts
Correct answer: Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts
Privileged user monitoring implements heightened audit controls including comprehensive logging, session recording, and real-time alerting specifically for high-privilege accounts.
Question 63: A governance board wants to reduce identity-related risk without increasing operational burden. Which IAM initiative best balances both goals?
- Expanding manual quarterly reviews to all user populations
- Removing all standing privileged access and requiring re-approval daily
- Requiring all users to request access through a help desk ticket
- Implementing risk-based access certification that focuses reviews on high-risk accounts (Correct answer)
Correct answer: Implementing risk-based access certification that focuses reviews on high-risk accounts
Risk-based certification focuses review effort on the highest-risk accounts and entitlements, reducing compliance burden while improving overall risk posture.
Question 64: What is encryption?
- Compressing files
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Deleting data
- Backing up data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 65: What does 'inherent risk' mean in the context of IAM security assessments?
- The residual risk after all controls are applied
- The risk level before any mitigating controls are in place (Correct answer)
- The risk accepted by executive leadership
- The risk transferred to a third-party vendor
Correct answer: The risk level before any mitigating controls are in place
Inherent risk is the raw or untreated risk exposure that exists before any security controls are implemented.
Question 66: What LDAP control (OID 1.2.840.113556.1.4.319) enables a client to page through large search result sets?
- Sort control
- Server-side Sorting control
- VLV (Virtual List View) control
- Simple Paged Results control (Correct answer)
Correct answer: Simple Paged Results control
The Simple Paged Results control (RFC 2696) allows clients to retrieve large search results in manageable pages by passing a cookie back and forth with the server.
Question 67: Which study approach is most effective for Authorization Frameworks material?
- Active recall with practice questions (Correct answer)
- Passive re-reading of notes
- Studying for very long sessions without breaks
- Highlighting all text
Correct answer: Active recall with practice questions
Active recall through practice questions is the most effective study method, as it strengthens memory retrieval pathways.
Question 68: What is User Behavior Analytics (UBA) in IAM?
- A network traffic analysis and optimization tool
- A security capability that detects anomalous user activity patterns indicating potential compromise (Correct answer)
- An employee productivity tracking and reporting system
- A marketing tool for analyzing user preferences
Correct answer: A security capability that detects anomalous user activity patterns indicating potential compromise
UBA applies machine learning to establish baseline behavior patterns for each user and alerts when deviations occur, helping detect compromised accounts and insider threats.
Question 69: What is Single Logout (SLO) in federated identity?
- Revoking all digital certificates issued to a user
- Logging out from one application while remaining logged in to others
- A protocol that terminates sessions across all federated service providers when a user logs out (Correct answer)
- Disabling a federation trust relationship between domains
Correct answer: A protocol that terminates sessions across all federated service providers when a user logs out
Single Logout (SLO) is a protocol that propagates a logout event across all federated Service Providers, terminating all of a user's sessions simultaneously.
Question 70: Which OAuth 2.0 token type is a short-lived credential used to access protected resources on behalf of a user?
- ID token
- Authorization code
- Access token (Correct answer)
- Refresh token
Correct answer: Access token
An access token is a short-lived credential presented by the client to the resource server to access protected resources on behalf of the resource owner.
Question 71: Which framework provides a structured approach to categorizing information systems and selecting security controls based on impact levels?
- NIST SP 800-53 (Correct answer)
- OWASP Top 10
- SOC 2 Type II
- ISO 27001
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a catalog of security and privacy controls organized around system impact levels (Low, Moderate, High).
Question 72: A governance policy requires that no single employee can create vendors AND approve payments. This is an example of:
- Role explosion
- Need-to-know principle
- Least privilege
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties (SoD) prevents a single individual from controlling a complete high-risk process, reducing fraud and error risk.
Question 73: What role does ethics play in Authorization Frameworks practice?
- It guides professional conduct and protects stakeholders (Correct answer)
- Ethics is optional in professional settings
- It only applies to managers
- It only matters for legal compliance
Correct answer: It guides professional conduct and protects stakeholders
Professional ethics provide frameworks for responsible decision-making, ensuring practitioners act in the best interest of those they serve.
Question 74: What distinguishes a 'business role' from a 'technical role' in IGA?
- Business roles expire annually; technical roles do not
- Business roles can only be assigned manually; technical roles are automated
- Business roles are defined by IT, technical roles by HR
- Business roles map job functions to entitlement sets; technical roles map directly to system permissions (Correct answer)
Correct answer: Business roles map job functions to entitlement sets; technical roles map directly to system permissions
Business roles are logical groupings aligned to job functions (e.g., 'Financial Analyst'), while technical roles represent specific system-level permission sets.
Question 75: What is phishing?
- A backup system
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
- A network scanning tool
- A type of firewall
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 76: Which approach best describes 'least privilege' as applied to OAuth 2.0 scopes?
- Caching broad scopes to improve application performance
- Requesting only the minimum scopes necessary for the current operation (Correct answer)
- Using admin scopes to simplify scope management
- Requesting all available scopes upfront to avoid multiple authorization prompts
Correct answer: Requesting only the minimum scopes necessary for the current operation
Least privilege in OAuth 2.0 means requesting only the scopes required for the specific task at hand, minimizing the potential damage if the access token is compromised.
Question 77: What differentiates step-up authentication from standard MFA?
- Step-up authentication triggers additional factors when elevated risk or privilege is detected (Correct answer)
- Step-up authentication is only used for mobile devices
- Step-up authentication permanently replaces passwords
- Step-up authentication always requires biometrics
Correct answer: Step-up authentication triggers additional factors when elevated risk or privilege is detected
Step-up authentication dynamically requires additional verification factors when a user attempts a higher-risk action or accesses sensitive resources during an existing session.
Question 78: What is multi-factor authentication (MFA)?
- Logging in from multiple devices
- Requiring two or more verification methods to confirm identity (Correct answer)
- Having multiple accounts
- Using multiple passwords
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 79: Which type of risk assessment uses numerical values and statistical models to quantify potential losses?
- Quantitative risk assessment (Correct answer)
- Residual risk assessment
- Qualitative risk assessment
- Inherent risk assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessments use financial metrics like Annual Loss Expectancy (ALE) to express risk in monetary terms.
Question 80: Which IGA capability allows organizations to model 'what-if' scenarios before granting access?
- Entitlement catalog
- Role simulation (Correct answer)
- Access request portal
- Joiner-Mover-Leaver workflow
Correct answer: Role simulation
Role simulation lets administrators preview the SoD impact and effective permissions of adding or removing a role before applying the change.
Question 81: What is the role of SAML metadata in federation?
- Storing hashed user passwords for federation partners
- Logging all authentication events for compliance reporting
- Encrypting user attribute data transmitted between parties
- Describing federation participants' endpoints, capabilities, and public certificates to enable automatic configuration (Correct answer)
Correct answer: Describing federation participants' endpoints, capabilities, and public certificates to enable automatic configuration
SAML metadata documents describe the technical endpoints, supported bindings, and public key certificates of federation participants, enabling partners to configure trust automatically.
Question 82: In Active Directory, what is the difference between a 'universal' group and a 'global' group?
- Universal groups can contain members from any domain in the forest; global groups can only contain members from their own domain (Correct answer)
- Universal groups are replicated only within a site; global groups are replicated forest-wide
- Universal groups apply to computers only; global groups apply to users only
- Universal groups can only be used for email distribution; global groups are for security
Correct answer: Universal groups can contain members from any domain in the forest; global groups can only contain members from their own domain
Universal groups can include members from any domain in the forest and are replicated to the Global Catalog, while global groups are limited to members from their own domain.
Question 83: What is a 'circle of trust' in federated identity management?
- A cryptographic algorithm for key exchange
- A group of organizations that share federation agreements and trust each other's identity assertions (Correct answer)
- A certificate authority hierarchy for issuing federation certificates
- An access control list governing intra-domain permissions
Correct answer: A group of organizations that share federation agreements and trust each other's identity assertions
A circle of trust is a federation of entities that agree to share services and accept each other's identity assertions within a mutually agreed-upon policy framework.
Question 84: Which authorization pattern is most appropriate when a microservice needs to make access decisions based on data it does not own, without coupling tightly to the owning service?
- Require all microservices to share a single database for authorization data
- Use a centralized Policy Decision Point (PDP) with an externalized policy engine (Correct answer)
- Embed ownership checks directly in each microservice's code
- Rely solely on API gateway-level coarse-grained access control
Correct answer: Use a centralized Policy Decision Point (PDP) with an externalized policy engine
A centralized PDP with an externalized policy engine (e.g., OPA, Cedar) decouples authorization logic from microservice code, enabling consistent policy enforcement without tight service coupling.
Question 85: Which identity lifecycle stage is most critical for preventing 'ghost accounts' that could be exploited after an employee departure?
- Deprovisioning (Correct answer)
- Authentication
- Provisioning
- Access recertification
Correct answer: Deprovisioning
Deprovisioning (offboarding) must promptly disable or delete accounts when users leave to prevent unauthorized post-departure access.
Question 86: Which IGA concept describes assigning access based on a user's verified attributes such as department, location, and clearance level?
- Attribute-Based Access Control (ABAC) (Correct answer)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC)
- Discretionary Access Control (DAC)
Correct answer: Attribute-Based Access Control (ABAC)
ABAC grants access dynamically based on evaluated attributes of the user, resource, and environment, enabling fine-grained, contextual access decisions.
Question 87: What is the primary purpose of threat analysis in IAM?
- To identify potential security risks that could compromise access to systems and data (Correct answer)
- To ensure that the network is optimized for performance
- To improve the authentication methods used by the organization
- To evaluate the effectiveness of disaster recovery plans
Correct answer: To identify potential security risks that could compromise access to systems and data
The primary purpose of threat analysis in IAM is to proactively identify potential security risks and vulnerabilities that could compromise access to systems and data. By understanding these threats, organizations can develop strategies and controls to mitigate them before they can be exploited.
Question 88: In IAM governance, 'toxic combinations' refer to:
- Two-factor authentication methods that conflict
- Roles that expire before they are assigned
- Combinations of permissions that violate segregation of duties (Correct answer)
- Accounts with both local and federated credentials
Correct answer: Combinations of permissions that violate segregation of duties
Toxic combinations are pairs or sets of entitlements that, when held by the same user, violate segregation of duties and create fraud or error risk.
Question 89: What does the 'sub' claim represent in a JWT ID token?
- A subordinate role assigned to the user
- The subscription level or tier of the user's account
- The sub-domain from which authentication was initiated
- Subject β the unique identifier for the authenticated user (Correct answer)
Correct answer: Subject β the unique identifier for the authenticated user
The 'sub' (Subject) claim in a JWT ID token contains the unique identifier for the authenticated user within the Identity Provider's system.
Question 90: What is the difference between authentication logging and authorization logging?
- Authorization logging records password changes while authentication logging records role assignments
- Authentication logging records identity verification events; authorization logging records access control decisions (Correct answer)
- Authentication logging is encrypted while authorization logging is stored in plain text
- There is no meaningful difference between the two types
Correct answer: Authentication logging records identity verification events; authorization logging records access control decisions
Authentication logging captures login and logout events that verify identity, while authorization logging records access control decisions β what resources were allowed or denied to authenticated users.
Question 91: Which protocol does SCIM (System for Cross-domain Identity Management) use as its transport layer?
- RADIUS over UDP
- SOAP over HTTPS
- REST over HTTPS (Correct answer)
- LDAP over TLS
Correct answer: REST over HTTPS
SCIM uses RESTful APIs over HTTPS to automate user provisioning and deprovisioning across systems.
Question 92: Which control helps prevent 'ghost accounts'βactive accounts belonging to users who have left the organization?
- IP allowlisting for all enterprise applications
- Periodic access reconciliation against the HR system (Correct answer)
- Single sign-on enforcement
- Mandatory password rotation every 30 days
Correct answer: Periodic access reconciliation against the HR system
Reconciling the IAM directory against the authoritative HR system on a scheduled basis detects accounts that should have been deprovisioned but weren't.
Question 93: In the context of IAM governance, a Segregation of Duties (SoD) violation occurs when:
- A role contains more than 50 permissions
- An administrator grants access without approval
- A user holds access rights that span the full lifecycle of a critical transaction (Correct answer)
- A user activates more than one role in a session
Correct answer: A user holds access rights that span the full lifecycle of a critical transaction
SoD violations exist when one person can initiate, approve, and complete a sensitive transaction without any checks, enabling fraud or error without detection.
Question 94: Under CCPA, what right allows California consumers to request that a business delete personal information collected about them?
- Right to non-discrimination
- Right to deletion (Correct answer)
- Right to portability
- Right to opt-out
Correct answer: Right to deletion
The CCPA Right to Deletion allows California consumers to request that businesses delete personal information collected, subject to certain exceptions.
Question 95: Which approach best handles identity lifecycle management for a large organization with multiple HR systems across subsidiaries?
- Allow each subsidiary to independently manage its own IAM with no central oversight
- Use a meta-directory or identity broker to aggregate authoritative data from all HR sources (Correct answer)
- Manually reconcile user data between systems using spreadsheets monthly
- Require all subsidiaries to migrate to a single HR system before IAM integration
Correct answer: Use a meta-directory or identity broker to aggregate authoritative data from all HR sources
A meta-directory or identity broker aggregates identity data from multiple authoritative sources, providing a unified view for lifecycle management without requiring HR system consolidation.
Question 96: What is 'Privileged Session Management' (PSM)?
- A tool for managing end-user session timeouts
- A capability that records, monitors, and controls sessions conducted by privileged users in real time (Correct answer)
- A system for managing user authentication session tokens
- A browser session management tool for IT help desk staff
Correct answer: A capability that records, monitors, and controls sessions conducted by privileged users in real time
Privileged Session Management records all keystrokes and actions during privileged user sessions, enabling real-time monitoring, intervention, and forensic replay after incidents.
Question 97: Under CMMC Level 2, which practice domain requires organizations to control access to CUI based on least privilege?
- Audit and Accountability (AU)
- Configuration Management (CM)
- Incident Response (IR)
- Access Control (AC) (Correct answer)
Correct answer: Access Control (AC)
CMMC Level 2 Access Control (AC) practices require limiting system access to authorized users and implementing least privilege for CUI protection.
Question 98: Which metric measures the average time it takes an organization to detect a security breach within its CIAM environment?
- Recovery Time Objective (RTO)
- Annual Loss Expectancy (ALE)
- Mean Time to Repair (MTTR)
- Mean Time to Detect (MTTD) (Correct answer)
Correct answer: Mean Time to Detect (MTTD)
MTTD (Mean Time to Detect) measures the average elapsed time between a breach occurring and the organization identifying it.
Question 99: What does 'document authenticity verification' aim to confirm during identity proofing?
- That the identity document is genuine and has not been tampered with or forged (Correct answer)
- That the document's expiration date is in the future
- That the document matches the format preferred by the relying party
- That the document has been scanned at sufficient resolution
Correct answer: That the identity document is genuine and has not been tampered with or forged
Document authenticity verification checks security features, holograms, machine-readable zones, and other indicators to confirm a presented document is genuine and unaltered.
Question 100: A user presents a smartcard to authenticate to a workstation. The workstation validates the certificate chain against a CRL. What does CRL stand for?
- Certificate Rotation Log
- Cryptographic Registration Ledger
- Certificate Revocation List (Correct answer)
- Certificate Renewal Link
Correct answer: Certificate Revocation List
A Certificate Revocation List (CRL) is a published list of digital certificates that have been revoked by the issuing CA before their expiration date.
Question 101: An organization wants to allow users to log in with their corporate credentials on a third-party SaaS application without sharing passwords. Which federation approach is most appropriate?
- Basic HTTP authentication
- Password vaulting
- LDAP direct bind
- SAML-based SSO (Correct answer)
Correct answer: SAML-based SSO
SAML-based SSO enables federated identity so users authenticate at the corporate IdP and the SaaS SP accepts the assertion, never receiving the user's password.
Question 102: An employee moves from Finance to Engineering. Under least privilege, which action is most appropriate for their Finance system access?
- Keep Finance access until the employee manually requests removal
- Revoke Finance access immediately upon role change (Correct answer)
- Downgrade Finance access to read-only for six months
- Retain Finance access for 90 days as a transition buffer
Correct answer: Revoke Finance access immediately upon role change
Least privilege requires revoking access to systems no longer needed for the new role immediately upon the mover event, not retaining it as a convenience.
CIAM β Certified Identity and Access Manager
The CIAM certification is offered by the Identity Management Institute and validates expertise in identity governance, access management, authentication, risk management, and regulatory compliance. The exam consists of 100 multiple-choice questions to be completed in 90 minutes with a 70% passing score.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds