Identity and Access Management Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity and Access Management flashcards as text
Which OAuth 2.0 grant type is most appropriate for a server-side web application that can securely store a client secret?
Answer: Authorization Code Grant
The Authorization Code Grant is the most secure OAuth 2.0 flow for server-side apps because it exchanges a short-lived code for tokens without exposing them in the browser.
A privileged access management (PAM) solution stores administrator passwords and rotates them after each use. Which PAM capability does this describe?
Answer: Password vaulting with check-out
Password vaulting with check-out allows admins to retrieve a password for one session; the vault automatically rotates it afterward, preventing password reuse.
Which directory protocol is most commonly used for querying and modifying user account information in enterprise environments?
Answer: LDAP
LDAP (Lightweight Directory Access Protocol) is the standard protocol for reading and writing to directory services like Active Directory.
A user requests elevated privileges only for the duration needed to perform a specific administrative task. Which concept does this represent?
Answer: Just-in-time privileged access
Just-in-time (JIT) privileged access grants elevated rights only when needed and revokes them immediately after, minimizing the window of exposure.
When an organization uses an external IdP to authenticate users and the application trusts that IdP's assertions, what is the application called?
Answer: Service Provider
In federated identity, the Service Provider (SP) relies on the Identity Provider (IdP) to authenticate users and accepts the IdP's identity assertions.
Which attack exploits the reuse of a previously captured authentication token to impersonate a legitimate user?
Answer: Replay attack
A replay attack intercepts and reuses a valid authentication token or message to gain unauthorized access without knowing the original credentials.
Which identity governance function periodically reviews whether existing user access rights remain appropriate and business-justified?
Answer: Access recertification (certification campaign)
Access recertification (also called access certification campaigns) requires managers to review and confirm or revoke their team members' existing access rights periodically.