CIMP Identity Lifecycle Management 2 — Questions and Answers
Question 1: What is the purpose of a 'reconciliation' process in identity lifecycle management?
- Resetting user passwords after expiration
- Comparing authoritative identity data with accounts in target systems to detect discrepancies (Correct answer)
- Merging duplicate user profiles
- Granting temporary elevated access for projects
Correct answer: Comparing authoritative identity data with accounts in target systems to detect discrepancies
Reconciliation compares the identity management system's authoritative data with actual accounts in connected systems to find and remediate inconsistencies.
Question 2: Which identity lifecycle event typically triggers immediate deprovisioning of all user access?
- An employee requests parental leave
- An employee is terminated (Correct answer)
- An employee receives a promotion
- An employee changes office location
Correct answer: An employee is terminated
Termination requires immediate deprovisioning to eliminate security risk, as former employees should lose all system access on their last day.
Question 3: What does a 'role catalog' provide in an identity lifecycle management program?
- A list of all user passwords stored in encrypted form
- A standardized set of predefined roles with associated entitlements mapped to job functions (Correct answer)
- A log of all provisioning and deprovisioning activities
- A directory of all external identity providers
Correct answer: A standardized set of predefined roles with associated entitlements mapped to job functions
A role catalog defines standardized roles aligned to job functions, each with a predefined set of entitlements, enabling consistent and auditable provisioning.
Question 4: An employee is on a leave of absence for 6 months. What is the recommended identity management approach?
- Permanently delete the account
- Disable the account and preserve it for reactivation upon return (Correct answer)
- Transfer the account ownership to the employee's manager
- Downgrade access to read-only permissions
Correct answer: Disable the account and preserve it for reactivation upon return
Disabling the account prevents unauthorized access during absence while preserving the identity record for seamless reactivation when the employee returns.
Question 5: Which metric is most useful for measuring the effectiveness of an organization's offboarding (leaver) process?
- Number of accounts provisioned per day
- Average time from termination to full account deprovisioning (Correct answer)
- Password complexity score across the organization
- Number of self-service requests completed monthly
Correct answer: Average time from termination to full account deprovisioning
The time from termination to full deprovisioning measures how quickly security risk is eliminated when an employee leaves, making it the key offboarding metric.
Question 6: What is 'birthright access' in the context of identity provisioning?
- Access granted based on seniority within the organization
- The baseline set of entitlements automatically granted to all new users upon joining (Correct answer)
- Access rights inherited from a manager's account
- Emergency access granted during a crisis event
Correct answer: The baseline set of entitlements automatically granted to all new users upon joining
Birthright access refers to the standard entitlements every new employee receives automatically, such as email and intranet access, regardless of their specific role.
Question 7: In identity lifecycle management, what is a 'Joiner' workflow typically initiated by?
- A help desk ticket submitted by the new employee
- An HR system event such as a new hire record being created (Correct answer)
- A manager manually requesting access through the IGA portal
- A security team review of pending access requests
Correct answer: An HR system event such as a new hire record being created
Joiner workflows are best triggered automatically by HR system events like a new hire record, ensuring provisioning begins immediately and consistently.
What is the purpose of a 'reconciliation' process in identity lifecycle management?