โ† All CSC Flashcard Decks

Identity and Access Management (IAM) Compliance Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Identity and Access Management (IAM) Compliance flashcards as text
  1. What does the principle of least privilege require in an IAM compliance context?

    Answer: Users should be granted only the minimum permissions necessary to perform their specific job functions

    The principle of least privilege limits each user's access to only what is required for their role, minimizing the attack surface and reducing insider threat risk.

  2. Which compliance framework explicitly mandates multi-factor authentication (MFA) for all remote access to cardholder data environments?

    Answer: PCI DSS

    PCI DSS Requirement 8.4 mandates MFA for all non-console administrative access and all remote access to the cardholder data environment (CDE).

  3. What is the primary compliance purpose of Privileged Access Management (PAM)?

    Answer: To monitor, secure, and control elevated access to critical systems and data

    PAM secures and monitors privileged accounts that have elevated rights, reducing the risk of insider threats and unauthorized access to critical resources.

  4. How frequently do most compliance frameworks (PCI DSS, SOX, ISO 27001) require access reviews to be conducted for privileged accounts?

    Answer: At least quarterly for privileged accounts, with general access reviewed at minimum annually

    Most compliance frameworks require periodic access reviews, with privileged access reviewed at least quarterly and standard user access reviewed at minimum annually to enforce least privilege.

  5. What does Role-Based Access Control (RBAC) use as the basis for assigning access permissions?

    Answer: The job roles defined within the organization

    RBAC assigns permissions based on defined organizational roles, ensuring users receive access appropriate to their job function, simplifying administration and supporting compliance.

  6. What is the compliance significance of Separation of Duties (SoD) in IAM?

    Answer: It requires critical tasks to be divided among multiple individuals to prevent fraud or errors

    Separation of duties ensures no single individual can control all aspects of a critical process, a key anti-fraud control required by frameworks like SOX, PCI DSS, and ISO 27001.

  7. Under most cybersecurity compliance frameworks, which combination of requirements applies to password policies?

    Answer: Minimum length, character complexity (uppercase, lowercase, numbers, special characters), and periodic rotation

    Compliance frameworks require passwords to meet minimum length, include mixed character types, and be rotated periodically to reduce the risk of credential compromise.