← All CySA+ Test Flashcard Decks

Identity and Access Management Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity and Access Management flashcards as text
  1. A threat actor compromises a domain controller and forges a Kerberos ticket-granting ticket (TGT) with a custom lifetime of 10 years using the KRBTGT hash. What type of attack is this?

    Answer: Golden Ticket attack

    A Golden Ticket attack uses the compromised KRBTGT account hash to forge valid Kerberos TGTs, granting the attacker persistent, domain-wide access that persists even after password resets.

  2. An attacker captures the NTLM hash of an administrator account from memory and uses it to authenticate to network services without cracking the password. What technique is being used?

    Answer: Pass-the-Hash

    Pass-the-Hash exploits NTLM authentication by using the stolen password hash directly for authentication without needing the plaintext password.

  3. Which CySA+ tool or technique would BEST help detect when a legitimate user account is exhibiting anomalous behavior such as logging in at unusual hours or accessing unusual resources?

    Answer: User and Entity Behavior Analytics (UEBA)

    UEBA establishes behavioral baselines for users and entities, then flags deviations such as unusual login times or abnormal data access patterns that may indicate account compromise or insider threat.

  4. An organization wants to enforce that its vendors can only access specific systems during business hours from approved IP addresses. Which access control model is MOST suited to enforce this policy?

    Answer: Attribute-Based Access Control (ABAC)

    ABAC makes access decisions based on multiple attributes — such as user identity, time of day, IP address, and resource type — making it the most flexible model for complex, context-aware policies.

  5. What is the primary security concern when an organization uses a shared service account with a static password for multiple automated processes?

    Answer: Accountability is lost and the password may never be rotated, increasing risk of undetected compromise

    Shared service accounts lack individual accountability, and static passwords are rarely rotated, creating long windows of exposure if the credential is compromised without detection.

  6. Which of the following BEST describes the purpose of an Identity Governance and Administration (IGA) solution?

    Answer: Providing automated access request, certification, and policy enforcement across the identity lifecycle

    IGA solutions automate provisioning, access reviews, role management, and policy enforcement across the full identity lifecycle to ensure compliance and reduce risk from excessive or inappropriate access.

  7. During an incident investigation, an analyst finds that an attacker used a compromised service account to query the Active Directory for all Service Principal Names (SPNs) and then cracked the resulting Kerberos service tickets offline. What attack technique does this describe?

    Answer: Kerberoasting

    Kerberoasting requests Kerberos service tickets for accounts with SPNs, then cracks the RC4-encrypted tickets offline to recover service account passwords, often targeting accounts with weak passwords.