CIAM Governance and Compliance 3 — Questions and Answers
Question 1: Which IAM audit technique uses automated comparison of current user access rights against an approved entitlement baseline?
- Penetration testing
- Variance analysis (Correct answer)
- Access recertification campaign
- Control self-assessment
Correct answer: Variance analysis
Variance analysis compares actual entitlements to an approved baseline, flagging differences that may indicate unauthorized or drifted access.
Question 2: Under NIST SP 800-53, which control family most directly governs access control policies and procedures?
- AU – Audit and Accountability
- AC – Access Control (Correct answer)
- IA – Identification and Authentication
- CM – Configuration Management
Correct answer: AC – Access Control
The AC (Access Control) family in NIST SP 800-53 contains controls for account management, access enforcement, and least privilege.
Question 3: A compliance auditor asks for evidence that privileged access is reviewed quarterly. Which IAM artifact best satisfies this request?
- Network topology diagram
- Completed access certification reports with timestamps (Correct answer)
- Firewall rule change logs
- User onboarding checklists
Correct answer: Completed access certification reports with timestamps
Completed access certification reports with timestamps demonstrate that privileged accounts were reviewed at the required frequency.
Question 4: In IAM governance, 'toxic combinations' refer to:
- Two-factor authentication methods that conflict
- Combinations of permissions that violate segregation of duties (Correct answer)
- Accounts with both local and federated credentials
- Roles that expire before they are assigned
Correct answer: Combinations of permissions that violate segregation of duties
Toxic combinations are pairs or sets of entitlements that, when held by the same user, violate segregation of duties and create fraud or error risk.
Question 5: Which regulation requires US federal agencies to use FIPS 201-compliant credentials for logical access to IT systems?
- FISMA (Correct answer)
- FERPA
- COPPA
- GLBA
Correct answer: FISMA
FISMA (Federal Information Security Modernization Act) mandates that federal agencies comply with NIST standards, including FIPS 201 for Personal Identity Verification.
Question 6: An access review finds that a developer has both 'deploy to production' and 'approve production changes' permissions. Which governance concept does remediating this violation address?
- Dual control
- Segregation of duties (Correct answer)
- Defense in depth
- Role explosion
Correct answer: Segregation of duties
Segregation of duties prevents a single person from controlling all steps of a critical process; separating deploy and approval rights enforces this principle.
Question 7: Under CCPA, what right allows California consumers to request that a business delete personal information collected about them?
- Right to portability
- Right to opt-out
- Right to deletion (Correct answer)
- Right to non-discrimination
Correct answer: Right to deletion
The CCPA Right to Deletion allows California consumers to request that businesses delete personal information collected, subject to certain exceptions.
Which IAM audit technique uses automated comparison of current user access rights against an approved entitlement baseline?