Identity and Access Management Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity and Access Management flashcards as text
Which IAM concept uses continuous evaluation of user behavior, device health, and context to make per-request access decisions rather than trusting the network perimeter?
Answer: Zero trust architecture
Zero trust architecture assumes no implicit trust based on network location and requires continuous verification of identity, device posture, and context for every access request.
A company discovers that a former employee's Active Directory account was disabled but their VPN certificate was never revoked. Which process failed?
Answer: Account de-provisioning / offboarding
Incomplete de-provisioning — failing to revoke all credentials including certificates — leaves residual access vectors open after an employee departs.
Which Kerberos attack forges a TGT using the compromised KRBTGT account hash, granting the attacker persistent and nearly unlimited domain access?
Answer: Golden ticket attack
A golden ticket attack uses the KRBTGT password hash to forge valid TGTs for any account, effectively giving the attacker domain-level persistence.
An organization implements context-aware authentication that increases scrutiny when login attempts occur from unusual countries. Which authentication approach does this describe?
Answer: Adaptive / risk-based authentication
Adaptive (risk-based) authentication dynamically adjusts the level of authentication challenge based on contextual risk signals such as location, device, or behavior anomalies.
Which standard defines a common framework for assurance levels in digital identity, classifying them as IAL, AAL, and FAL?
Answer: NIST SP 800-63
NIST SP 800-63 Digital Identity Guidelines defines Identity Assurance Level (IAL), Authenticator Assurance Level (AAL), and Federation Assurance Level (FAL).
Which technique involves mapping existing user permissions to derive a normalized, minimal set of roles that covers the organization's access needs?
Answer: Role mining
Role mining analyzes existing user-to-permission assignments to discover natural role groupings, enabling organizations to build RBAC structures from real access patterns.
A user is authenticated but the system checks additional attributes — department, project membership, and data sensitivity level — before granting access to a document. Which model is being applied?
Answer: Attribute-based access control
ABAC evaluates multiple attributes of the subject, resource, and environment simultaneously to make fine-grained access decisions beyond simple role membership.