CIMP Identity Lifecycle Management 1 — Questions and Answers
Question 1: Which term describes the process of automatically creating user accounts and assigning entitlements when an employee joins an organization?
- Deprovisioning
- Provisioning (Correct answer)
- Reconciliation
- Attestation
Correct answer: Provisioning
Provisioning is the automated or manual process of creating accounts and granting appropriate access rights when a user onboards.
Question 2: The 'joiner-mover-leaver' model in identity lifecycle management refers to which three phases?
- Hire, Transfer, Terminate (Correct answer)
- Create, Modify, Delete
- Authenticate, Authorize, Audit
- Request, Approve, Provision
Correct answer: Hire, Transfer, Terminate
The joiner-mover-leaver model maps to hiring (joiner), role/department changes (mover), and termination (leaver) in an employee's lifecycle.
Question 3: What is the primary risk associated with orphaned accounts in an identity management system?
- Increased provisioning costs
- Unauthorized access by former employees or attackers (Correct answer)
- Reduced directory performance
- Duplicate identity records
Correct answer: Unauthorized access by former employees or attackers
Orphaned accounts belong to users who no longer require access, creating a security gap that former employees or attackers could exploit.
Question 4: Which process ensures that user access rights remain accurate and aligned with current job roles over time?
- Initial provisioning
- Access certification/attestation (Correct answer)
- Role mining
- Self-service password reset
Correct answer: Access certification/attestation
Access certification (attestation) is a periodic review process where managers confirm or revoke user entitlements to maintain least-privilege alignment.
Question 5: When an employee transfers from the finance department to the IT department, which identity lifecycle best practice should be applied?
- Add new entitlements without removing old ones
- Disable the account until HR approval
- Remove finance entitlements and grant IT entitlements (Correct answer)
- Create a second account for the new role
Correct answer: Remove finance entitlements and grant IT entitlements
When a mover changes roles, old entitlements must be revoked and new ones granted to prevent accumulation of excessive privileges (privilege creep).
Question 6: What is 'privilege creep' in the context of identity lifecycle management?
- A method for gradually escalating administrator rights
- The gradual accumulation of access rights beyond what a user's current role requires (Correct answer)
- A technique for detecting unauthorized privilege escalation
- The process of slowly reducing excessive permissions
Correct answer: The gradual accumulation of access rights beyond what a user's current role requires
Privilege creep occurs when users accumulate access permissions over time as roles change but old entitlements are never removed.
Question 7: Which automated workflow capability is most critical for reducing the time-to-provision for new employees?
- Manual ticket-based access requests
- Role-based provisioning triggered by HR system events (Correct answer)
- Weekly batch reconciliation jobs
- Self-service access request portals only
Correct answer: Role-based provisioning triggered by HR system events
Role-based provisioning triggered by HR system events automates account creation and entitlement assignment the moment a hire event occurs, minimizing delays.
Which term describes the process of automatically creating user accounts and assigning entitlements when an employee joins an organization?