Identity and Access Management (IAM) Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity and Access Management (IAM) Compliance flashcards as text
What does identity lifecycle management encompass in an IAM compliance program?
Answer: The end-to-end management of user identities from creation through modification to deprovisioning
Identity lifecycle management covers the complete process of provisioning, modifying, and deprovisioning user accounts and access rights throughout an employee's tenure to maintain compliance.
What is the primary compliance benefit of implementing Single Sign-On (SSO)?
Answer: It centralizes authentication and creates a unified audit trail across multiple systems
SSO centralizes authentication events into a single log source, making it easier to audit access across multiple systems and satisfying compliance requirements for access monitoring.
What is the core IAM principle of the Zero Trust security model?
Answer: Never trust, always verify — every access request must be authenticated and authorized regardless of location
Zero Trust eliminates implicit trust based on network location, requiring continuous verification of every user and device for every access request, aligning with modern compliance mandates.
What is Just-in-Time (JIT) access provisioning and why does it support compliance?
Answer: Providing elevated access only for the duration of a specific task and automatically revoking it afterward
JIT provisioning grants elevated permissions only when needed and revokes them immediately after, minimizing the window of standing privileged access and reducing compliance risk.
Which access control model grants permissions based on security labels assigned to resources and user clearance levels?
Answer: Mandatory Access Control (MAC)
MAC enforces access based on predefined security classifications (labels) and user clearance levels, with no user discretion allowed, commonly used in government and defense environments.
What is federated identity management and how does it support compliance?
Answer: A framework that enables identity information to be shared securely across organizational boundaries using trust relationships
Federated identity management uses trust frameworks (such as SAML or OAuth) to share identity assertions across organizations, enabling secure access while maintaining centralized audit and governance.
Why is comprehensive access event logging considered a critical IAM compliance control?
Answer: It creates an audit trail documenting who accessed what resources and when, supporting forensic investigations and compliance audits
Access event logging creates an immutable audit trail of authentication and authorization activity required by frameworks like PCI DSS, HIPAA, and SOX to demonstrate accountability and support incident investigation.