CIMP CIMP Identity Governance & Administration 2 — Questions and Answers
Question 1: Which US federal regulation most directly drives the need for access certifications and SoD controls in publicly traded companies?
- HIPAA
- SOX (Sarbanes-Oxley Act) (Correct answer)
- COPPA
- CAN-SPAM
Correct answer: SOX (Sarbanes-Oxley Act)
SOX Section 404 requires management to assess internal controls over financial reporting, making IGA and SoD controls essential for compliance.
Question 2: What is an 'orphan account' in the context of identity governance?
- An account with a weak password
- An account that no longer has an associated active user (Correct answer)
- A shared service account
- An account pending provisioning
Correct answer: An account that no longer has an associated active user
Orphan accounts are credentials that remain active after the associated user has left or changed roles, posing a significant security risk.
Question 3: In IGA, what is 'birthright access'?
- Access granted based on years of seniority
- The standard set of access rights automatically provisioned to all users in a given role upon hire (Correct answer)
- Emergency access for disaster recovery
- Access inherited from a previous employee
Correct answer: The standard set of access rights automatically provisioned to all users in a given role upon hire
Birthright access defines the baseline entitlements every user in a particular role receives automatically as part of the standard onboarding process.
Question 4: What distinguishes a Role-Based Access Control (RBAC) model from an Attribute-Based Access Control (ABAC) model?
- RBAC grants access based on job roles, while ABAC uses dynamic attributes like location, time, or device (Correct answer)
- RBAC is only used for cloud systems
- ABAC does not support audit trails
- RBAC requires biometric authentication
Correct answer: RBAC grants access based on job roles, while ABAC uses dynamic attributes like location, time, or device
RBAC assigns permissions to predefined roles, whereas ABAC makes dynamic access decisions based on multiple user, resource, and environmental attributes.
Question 5: Why is automated provisioning preferred over manual provisioning in large enterprises?
- It eliminates the need for security policies
- It reduces errors, speeds up access delivery, and ensures consistent policy enforcement (Correct answer)
- It bypasses approval workflows
- It removes the need for access reviews
Correct answer: It reduces errors, speeds up access delivery, and ensures consistent policy enforcement
Automated provisioning enforces consistent policies, reduces human error, and dramatically shortens the time required to grant or revoke access at scale.
Question 6: What is 'entitlement creep' (also called privilege creep) in IGA?
- A vulnerability in entitlement APIs
- The gradual accumulation of access rights beyond what a user currently needs (Correct answer)
- A type of phishing attack
- A method for expanding role definitions
Correct answer: The gradual accumulation of access rights beyond what a user currently needs
Entitlement creep occurs when users accumulate permissions over time through role changes without having old access removed, violating the least privilege principle.
Which US federal regulation most directly drives the need for access certifications and SoD controls in publicly traded companies?