CIAM Identity Governance 3 — Questions and Answers
Question 1: Which IGA capability allows organizations to model 'what-if' scenarios before granting access?
- Role simulation (Correct answer)
- Access request portal
- Joiner-Mover-Leaver workflow
- Entitlement catalog
Correct answer: Role simulation
Role simulation lets administrators preview the SoD impact and effective permissions of adding or removing a role before applying the change.
Question 2: How does identity governance support compliance with regulations like SOX and HIPAA?
- By encrypting all PII stored in HR systems
- By enforcing access controls and maintaining auditable entitlement records (Correct answer)
- By replacing passwords with biometrics across all systems
- By limiting network access to only on-premises devices
Correct answer: By enforcing access controls and maintaining auditable entitlement records
IGA provides the audit trails, certification records, and policy enforcement needed to demonstrate that access to regulated data is appropriately controlled.
Question 3: A user transfers from Finance to Marketing. Which IGA process should automatically adjust their access?
- Joiner workflow
- Mover workflow (Correct answer)
- Leaver workflow
- Certification campaign
Correct answer: Mover workflow
The Mover workflow handles internal transfers, revoking role-based access from the old position and provisioning access appropriate for the new one.
Question 4: What distinguishes a 'business role' from a 'technical role' in IGA?
- Business roles are defined by IT, technical roles by HR
- Business roles map job functions to entitlement sets; technical roles map directly to system permissions (Correct answer)
- Business roles can only be assigned manually; technical roles are automated
- Business roles expire annually; technical roles do not
Correct answer: Business roles map job functions to entitlement sets; technical roles map directly to system permissions
Business roles are logical groupings aligned to job functions (e.g., 'Financial Analyst'), while technical roles represent specific system-level permission sets.
Question 5: Which approach to role definition starts by analyzing existing user-to-entitlement assignments to discover implicit roles?
- Top-down role engineering
- Bottom-up role mining (Correct answer)
- Peer group analysis
- Birthright provisioning
Correct answer: Bottom-up role mining
Bottom-up role mining uses data analytics on existing entitlement assignments to identify common access patterns and suggest role definitions.
Question 6: In identity governance, what is the 'entitlement catalog'?
- A log of all failed access requests
- A centralized, searchable inventory of all available permissions and resources (Correct answer)
- A list of accounts that have been deprovisioned
- A record of all SoD violations found during the last review
Correct answer: A centralized, searchable inventory of all available permissions and resources
The entitlement catalog provides a structured, business-friendly view of all permissions available for request, enabling self-service access management.
Question 7: Which governance control prevents a user from approving their own access request?
- Dual control
- Self-approval restriction (Correct answer)
- Mandatory vacation policy
- Least privilege enforcement
Correct answer: Self-approval restriction
Self-approval restrictions are a governance control that routes access requests to a different approver when the requester and approver would otherwise be the same person.
Which IGA capability allows organizations to model 'what-if' scenarios before granting access?