โ† All CSS Flashcard Decks

CSS Identity & Access Management Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSS Identity & Access Management flashcards as text
  1. What is the principle of least privilege in identity and access management?

    Answer: Users are granted only the minimum permissions necessary to perform their job functions

    Least privilege limits the blast radius of a compromised account by ensuring users can only access what they need for their specific role.

  2. What does multi-factor authentication (MFA) require beyond a username and password?

    Answer: At least one additional verification factor such as a token, biometric, or push notification

    MFA combines something you know (password) with something you have (token) or something you are (biometric) to reduce account takeover risk.

  3. Which access control model grants permissions based on a user's job role rather than individual identity?

    Answer: Role-Based Access Control (RBAC)

    RBAC assigns permissions to roles, and users are granted access by being assigned to appropriate roles, simplifying administration at scale.

  4. What is credential stuffing and how does it differ from brute-force attacks?

    Answer: Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations

    Credential stuffing relies on real credentials from previous data breaches, making it more effective than random brute-force guessing.

  5. What is the purpose of a privileged access workstation (PAW)?

    Answer: A hardened, dedicated workstation used exclusively for privileged administrative tasks

    A PAW is a dedicated, highly secured device used only for admin tasks, reducing exposure to phishing and malware that could compromise privileged credentials.

  6. What does single sign-on (SSO) provide to enterprise users?

    Answer: Access to multiple applications using one set of credentials authenticated once

    SSO allows users to authenticate once with an identity provider and gain access to multiple connected applications without re-entering credentials.