โ† All CSS Flashcard Decks

CSS Identity & Access Management Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSS Identity & Access Management flashcards as text
  1. Which IAM concept involves automatically removing access rights when they are no longer needed?

    Answer: Access certification and deprovisioning

    Regular access reviews (certifications) and automated deprovisioning ensure that users who change roles or leave the organization do not retain unnecessary access.

  2. What is the difference between authentication and authorization in IAM?

    Answer: Authentication verifies identity; authorization determines what an authenticated identity is permitted to do

    Authentication confirms who you are, while authorization determines what resources and actions you are permitted to access once your identity is confirmed.

  3. What is a federated identity in the context of IAM?

    Answer: An identity that is trusted and shared across multiple organizations or systems using a common standard

    Federated identity allows users to authenticate with one organization's identity provider and access resources at a partner organization without creating separate accounts.

  4. Which attack targets authentication systems by using previously captured valid authentication tokens?

    Answer: Pass-the-ticket / pass-the-hash attack

    Pass-the-hash and pass-the-ticket attacks use stolen authentication tokens to authenticate as a victim without knowing the actual password.

  5. What is the security purpose of just-in-time (JIT) privileged access?

    Answer: Grants elevated privileges only for the duration needed, then automatically revokes them

    JIT access reduces the standing privilege attack surface by provisioning elevated rights only when requested and revoking them immediately after the task is complete.

  6. Which protocol is widely used for enterprise federated authentication and SSO?

    Answer: SAML (Security Assertion Markup Language)

    SAML is an XML-based open standard for exchanging authentication and authorization data between identity providers and service providers.