MDM Security and Access Control 2 — Questions and Answers
Question 1: In Informatica MDM, which security model controls access at the individual record level rather than the object level?
- Object-level security
- Row-level security (Correct answer)
- Column-level security
- Field-level security
Correct answer: Row-level security
Row-level security in Informatica MDM restricts which records a user can view or modify based on data values or organizational hierarchy.
Question 2: What mechanism does Informatica MDM use to enforce field-level security on sensitive attributes like SSN or credit card numbers?
- Column masking policies (Correct answer)
- Trust scores
- Business entity services
- Cleanse functions
Correct answer: Column masking policies
Column masking policies in MDM Hub allow administrators to hide or obfuscate sensitive field values from unauthorized users.
Question 3: Which Informatica MDM component handles authentication when integrating with an enterprise LDAP directory?
- Hub Server (Correct answer)
- Process Server
- ActiveVOS
- Resource Kit
Correct answer: Hub Server
The Hub Server is responsible for LDAP integration and delegates authentication to the external directory service.
Question 4: A user in Informatica MDM can view records but cannot promote them to the best version of truth. Which privilege is most likely missing?
- READ privilege
- MERGE privilege
- PROMOTE privilege (Correct answer)
- EXECUTE privilege
Correct answer: PROMOTE privilege
The PROMOTE privilege specifically controls the ability to consolidate records and establish the best version of truth in MDM Hub.
Question 5: In Informatica MDM's security architecture, what is the purpose of a 'secure resource'?
- An encrypted data store for master records
- A protected MDM function or data object controlled by privileges (Correct answer)
- A VPN tunnel between MDM components
- A read-only copy of the ORS database
Correct answer: A protected MDM function or data object controlled by privileges
A secure resource in MDM Hub is any application function or data object (such as a base object or package) that can be protected by assigning privileges to user roles.
Question 6: Which Informatica MDM feature allows different users to see different subsets of the same base object records based on their organizational context?
- Hierarchy Manager security
- Data stewardship roles
- Secure resources
- Data filters (Correct answer)
Correct answer: Data filters
Data filters in Informatica MDM restrict the records a user can access by appending filter conditions to queries based on user attributes.
Question 7: When configuring Informatica MDM to use SAML-based single sign-on, which component acts as the service provider?
- Identity Resolution Engine
- Hub Console
- MDM Hub Server (Correct answer)
- Siperian BPM
Correct answer: MDM Hub Server
The MDM Hub Server acts as the SAML service provider, relying on an external identity provider to authenticate users before granting access.
In Informatica MDM, which security model controls access at the individual record level rather than the object level?