โ† All CSS Flashcard Decks

CSS Identity & Access Management Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSS Identity & Access Management flashcards as text
  1. What is an orphaned account and why is it a security risk?

    Answer: An account no longer associated with an active user that may be exploited by attackers

    Orphaned accounts belong to users who have left the organization but were not properly deprovisioned, creating an entry point for attackers.

  2. Which standard is used to automate the provisioning and deprovisioning of user accounts across systems?

    Answer: SCIM (System for Cross-domain Identity Management)

    SCIM is an open API standard that automates user lifecycle management, enabling systems to create, update, and delete accounts automatically across identity providers and applications.

  3. What does the term 'separation of duties' mean in access control?

    Answer: No single user has enough access to commit fraud or error without detection from another user

    Separation of duties requires that critical tasks be divided among multiple individuals so no single person can complete a sensitive process unilaterally.

  4. What is behavioral analytics in the context of IAM security?

    Answer: Uses baseline behavior patterns to detect anomalous user activity that may indicate account compromise

    User and entity behavior analytics (UEBA) establishes baselines of normal activity and flags deviations such as unusual login times, locations, or data access patterns.

  5. Which IAM control helps prevent privilege escalation by ensuring users cannot grant themselves higher permissions than they currently hold?

    Answer: Constrained delegation and permission boundary enforcement

    Constrained delegation and IAM permission boundaries ensure that even if an account is compromised, the attacker cannot escalate to permissions beyond those already assigned.

  6. What is the primary function of a privileged access management (PAM) solution?

    Answer: Securely manages, monitors, and audits access to privileged accounts and credentials

    PAM solutions vault privileged credentials, enforce access workflows, and record privileged sessions to prevent misuse and support forensic investigation.