Security and Access Control Flashcards
7 cards from real MDM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Access Control flashcards as text
In Informatica MDM, which database schema stores the security metadata including user roles and privileges?
Answer: CMX_SYSTEM schema
The CMX_SYSTEM schema is the MDM Hub's administrative database that stores system-level metadata including security configuration like roles and privileges.
What happens in Informatica MDM when a user belongs to multiple roles that have conflicting privileges on the same secure resource?
Answer: The least restrictive privilege always wins
Informatica MDM uses a permissive privilege model where the effective permission is the union of all privileges granted across all assigned roles.
Which Informatica MDM security feature controls whether a user can see the change history (cross-reference records) of a master object?
Answer: Cross-reference read privilege
The cross-reference read privilege specifically controls a user's ability to view the source system contributions and history of a master record.
An Informatica MDM implementation uses Hierarchy Manager. Which additional security element must be configured to restrict access to specific hierarchy nodes?
Answer: HM relationship base object privileges
Hierarchy Manager relationship base object privileges control which hierarchy relationships and nodes a user can view or modify within the Hierarchy Manager.
In Informatica MDM, what is the effect of granting a role the EXECUTE privilege on a Cleanse function?
Answer: The role can invoke the cleanse function via API calls
The EXECUTE privilege on a cleanse function allows the assigned role to invoke that function through API or batch operations.
Which Informatica MDM security practice ensures that service accounts used by ETL processes follow least-privilege principles?
Answer: Creating dedicated roles with only the specific base object and package privileges needed
Least-privilege for ETL service accounts means creating custom roles that grant only the specific READ, CREATE, or UPDATE privileges required for those integration processes.
When Informatica MDM is deployed in a multi-tenant environment, what isolates the security configurations of each tenant?
Answer: Separate ORS databases with distinct role configurations
In multi-tenant MDM deployments, each tenant typically has its own Operational Reference Store with its own isolated set of roles, users, and privilege assignments.