← All CAP Flashcard Decks

Identity & Access Management Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity & Access Management flashcards as text
  1. Under the RMF, which document formally establishes the boundaries of a system and identifies the individuals responsible for its security?

    Answer: System Security Plan (SSP)

    The SSP defines the system boundary, describes controls in place, and identifies the system owner and authorizing official.

  2. Which NIST SP 800-63 assurance level requires proof of identity with in-person or supervised remote proofing and binding to a hardware-based authenticator?

    Answer: IAL3

    IAL3 mandates in-person or supervised remote identity proofing with a physical or biometric comparison tied to a hardware authenticator.

  3. A user's access to a classified database is determined solely by their job role and does not account for individual permissions. This is an example of which access control model?

    Answer: Role-Based Access Control (RBAC)

    RBAC grants access based on predefined roles assigned to users rather than individual identity attributes.

  4. When an organization implements privileged access workstations (PAWs), what primary risk is being mitigated?

    Answer: Credential theft through malware on general-use endpoints

    PAWs isolate privileged credentials from internet-exposed workstations, reducing the risk of credential harvesting by malware.

  5. Which federation protocol uses JSON Web Tokens (JWTs) to convey identity claims between an authorization server and a resource server?

    Answer: OAuth 2.0 with OpenID Connect

    OpenID Connect layered on OAuth 2.0 uses JWTs (ID tokens) to communicate authenticated user identity claims.

  6. An authorizing official receives an SSP but the system owner requests waiver of a required control due to an operational constraint. What document captures this accepted risk?

    Answer: Risk Acceptance Memo

    A Risk Acceptance Memo (or formal risk acceptance document) is signed by the AO to acknowledge and accept residual risk from an unimplemented control.

  7. Under NIST SP 800-53, which control family directly addresses user provisioning, account types, and least privilege enforcement?

    Answer: AC – Access Control

    The AC control family covers account management (AC-2), least privilege (AC-6), and access enforcement across all account types.