CIAM CIAM Audit and Monitoring 1 — Questions and Answers
Question 1: What is the primary purpose of IAM audit logs?
- Improving application response time
- Providing a record of who accessed what resources and when for security and compliance (Correct answer)
- Storing encrypted user passwords for recovery
- Managing network bandwidth allocation
Correct answer: Providing a record of who accessed what resources and when for security and compliance
IAM audit logs capture authentication events, access decisions, and administrative changes to support incident investigations, compliance audits, and accountability.
Question 2: What does 'non-repudiation' mean in the context of IAM auditing?
- The ability to refuse an access request
- Ensuring a user cannot deny having performed an authenticated action (Correct answer)
- Preventing unauthorized users from accessing the system
- Encrypting audit logs to protect their contents
Correct answer: Ensuring a user cannot deny having performed an authenticated action
Non-repudiation ensures that users cannot deny performing actions by providing cryptographically linked evidence tying actions to their authenticated identity.
Question 3: What is a SIEM system in the context of IAM monitoring?
- A Single Identity Entry Module for centralizing accounts
- A Security Information and Event Management system that aggregates and correlates security logs (Correct answer)
- A password management system for enterprise users
- A certificate authority for issuing identity certificates
Correct answer: A Security Information and Event Management system that aggregates and correlates security logs
A SIEM aggregates security logs from multiple sources, correlates events using rules and analytics, and provides real-time alerting for potential security incidents including IAM anomalies.
Question 4: What is User Behavior Analytics (UBA) in IAM?
- A marketing tool for analyzing user preferences
- A security capability that detects anomalous user activity patterns indicating potential compromise (Correct answer)
- An employee productivity tracking and reporting system
- A network traffic analysis and optimization tool
Correct answer: A security capability that detects anomalous user activity patterns indicating potential compromise
UBA applies machine learning to establish baseline behavior patterns for each user and alerts when deviations occur, helping detect compromised accounts and insider threats.
Question 5: What is the purpose of access certification campaigns?
- Certifying IAM administrators through formal examinations
- Periodically verifying that users retain only appropriate access rights by having managers review and approve (Correct answer)
- Issuing digital identity certificates to new employees
- Testing IAM system performance under peak load conditions
Correct answer: Periodically verifying that users retain only appropriate access rights by having managers review and approve
Access certification campaigns periodically require managers or system owners to review and confirm that each user's access rights remain appropriate for their current role.
Question 6: What is 'privileged user monitoring'?
- Monitoring only non-administrative standard users
- Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts (Correct answer)
- A password complexity monitoring tool for admin accounts
- Network-level monitoring of privileged user workstations
Correct answer: Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts
Privileged user monitoring implements heightened audit controls including comprehensive logging, session recording, and real-time alerting specifically for high-privilege accounts.
What is the primary purpose of IAM audit logs?