← All CISSP Flashcard Decks

Identity and Access Management Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity and Access Management flashcards as text
  1. Which IAM concept uses continuous evaluation of user behavior, device health, and context to make per-request access decisions rather than trusting the network perimeter?

    Answer: Zero trust architecture

    Zero trust architecture assumes no implicit trust based on network location and requires continuous verification of identity, device posture, and context for every access request.

  2. A company discovers that a former employee's Active Directory account was disabled but their VPN certificate was never revoked. Which process failed?

    Answer: Account de-provisioning / offboarding

    Incomplete de-provisioning — failing to revoke all credentials including certificates — leaves residual access vectors open after an employee departs.

  3. Which Kerberos attack forges a TGT using the compromised KRBTGT account hash, granting the attacker persistent and nearly unlimited domain access?

    Answer: Golden ticket attack

    A golden ticket attack uses the KRBTGT password hash to forge valid TGTs for any account, effectively giving the attacker domain-level persistence.

  4. An organization implements context-aware authentication that increases scrutiny when login attempts occur from unusual countries. Which authentication approach does this describe?

    Answer: Adaptive / risk-based authentication

    Adaptive (risk-based) authentication dynamically adjusts the level of authentication challenge based on contextual risk signals such as location, device, or behavior anomalies.

  5. Which standard defines a common framework for assurance levels in digital identity, classifying them as IAL, AAL, and FAL?

    Answer: NIST SP 800-63

    NIST SP 800-63 Digital Identity Guidelines defines Identity Assurance Level (IAL), Authenticator Assurance Level (AAL), and Federation Assurance Level (FAL).

  6. Which technique involves mapping existing user permissions to derive a normalized, minimal set of roles that covers the organization's access needs?

    Answer: Role mining

    Role mining analyzes existing user-to-permission assignments to discover natural role groupings, enabling organizations to build RBAC structures from real access patterns.

  7. A user is authenticated but the system checks additional attributes — department, project membership, and data sensitivity level — before granting access to a document. Which model is being applied?

    Answer: Attribute-based access control

    ABAC evaluates multiple attributes of the subject, resource, and environment simultaneously to make fine-grained access decisions beyond simple role membership.