CIMP CIMP Identity Governance & Administration 1 — Questions and Answers
Question 1: What is the primary goal of Identity Governance and Administration (IGA) in an enterprise?
- Maximize network bandwidth
- Ensure the right individuals have appropriate access to the right resources (Correct answer)
- Reduce hardware costs
- Automate all IT helpdesk tickets
Correct answer: Ensure the right individuals have appropriate access to the right resources
IGA ensures that access rights are properly assigned, reviewed, and enforced across all enterprise systems.
Question 2: Which IGA process involves periodically reviewing user access rights to confirm they remain appropriate?
- Provisioning
- Access certification (Correct answer)
- Role mining
- Directory synchronization
Correct answer: Access certification
Access certification (also called access reviews or attestation) is the process of formally validating that current user entitlements are still justified.
Question 3: In IGA, what does 'role mining' refer to?
- Extracting passwords from role accounts
- Analyzing existing access assignments to discover natural role groupings (Correct answer)
- Creating new admin roles manually
- Auditing privileged accounts
Correct answer: Analyzing existing access assignments to discover natural role groupings
Role mining analyzes existing entitlement data to identify patterns and define roles that reflect actual business functions.
Question 4: What is a Separation of Duties (SoD) conflict in identity governance?
- A user holding two positions in different departments
- A situation where one user has access rights that together could enable fraud or error (Correct answer)
- A policy that restricts remote work
- A conflict between two IAM vendors
Correct answer: A situation where one user has access rights that together could enable fraud or error
SoD conflicts occur when a single user has permissions to perform two or more steps of a sensitive process that should require multiple people.
Question 5: Which of the following best describes a 'Joiner-Mover-Leaver' (JML) process in IGA?
- A workflow for migrating databases
- The lifecycle management of user identities from onboarding through role changes to offboarding (Correct answer)
- A network segmentation strategy
- A process for rotating encryption keys
Correct answer: The lifecycle management of user identities from onboarding through role changes to offboarding
The JML process manages identity lifecycle events: provisioning access for new hires, adjusting access during role changes, and revoking access upon departure.
Question 6: What is the 'least privilege' principle as applied in IGA?
- Users should have as few passwords as possible
- Users should be granted only the minimum access rights necessary to perform their job functions (Correct answer)
- Privileged accounts should never be audited
- Admins should share a single account
Correct answer: Users should be granted only the minimum access rights necessary to perform their job functions
Least privilege limits each user's access rights to only what is required for their role, reducing the attack surface and risk of misuse.
What is the primary goal of Identity Governance and Administration (IGA) in an enterprise?