CIAM Identity Lifecycle 2 β Questions and Answers
Question 1: During the joiner process, which attribute is typically used as the authoritative source for creating a new digital identity in an IAM system?
- Employee's personal email address
- HR system employee record (Correct answer)
- IT helpdesk ticket number
- Manager's approval email
Correct answer: HR system employee record
The HR system serves as the system of record and authoritative source for new hire data used to create digital identities.
Question 2: What is the primary risk of failing to deprovision access promptly when an employee resigns?
- Increased licensing costs
- Orphaned accounts that may be exploited (Correct answer)
- Slower onboarding for replacements
- Compliance with GDPR deletion requests
Correct answer: Orphaned accounts that may be exploited
Orphaned accounts from departed employees remain active attack surfaces that threat actors can exploit using stolen or guessed credentials.
Question 3: In identity lifecycle management, what distinguishes a 'mover' event from a 'joiner' event?
- Mover events create new accounts while joiner events modify existing ones
- Mover events involve role or department changes for existing employees (Correct answer)
- Mover events apply only to contractors, not full-time staff
- Mover events require executive approval unlike joiner events
Correct answer: Mover events involve role or department changes for existing employees
A mover event occurs when an existing employee changes roles, departments, or locations, requiring access adjustments rather than new account creation.
Question 4: Which provisioning model automatically grants access based on a user's role assignment without requiring individual approval?
- Delegated provisioning
- Role-based automated provisioning (Correct answer)
- Self-service provisioning
- Manual provisioning
Correct answer: Role-based automated provisioning
Role-based automated provisioning assigns entitlements automatically when a role is assigned, reducing manual effort and provisioning delays.
Question 5: What is 'birthright access' in the context of identity lifecycle management?
- Access granted based on an employee's seniority level
- A baseline set of permissions every new joiner receives automatically (Correct answer)
- Rights inherited from a predecessor in the same role
- Emergency access granted at account creation
Correct answer: A baseline set of permissions every new joiner receives automatically
Birthright access refers to the minimum set of entitlements provisioned automatically to all new employees regardless of their specific role.
Question 6: During offboarding, which action should be performed FIRST to minimize risk when an employee is terminated for cause?
- Archiving the user's email
- Disabling the account immediately (Correct answer)
- Notifying IT to reclaim hardware
- Submitting an HR termination form
Correct answer: Disabling the account immediately
Immediate account disablement prevents the terminated employee from accessing systems while other offboarding tasks are completed.
Question 7: What is the purpose of an identity lifecycle policy's 'dormancy' threshold?
- To define how long a password remains valid before expiry
- To specify when an inactive account should be flagged or disabled (Correct answer)
- To set the maximum session duration for authenticated users
- To determine how long audit logs are retained
Correct answer: To specify when an inactive account should be flagged or disabled
A dormancy threshold defines the period of inactivity after which an account is automatically flagged, disabled, or reviewed to reduce the attack surface.
During the joiner process, which attribute is typically used as the authoritative source for creating a new digital identity in an IAM system?