← All CAP Flashcard Decks

Identity & Access Management Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity & Access Management flashcards as text
  1. A cloud service provider maintains shared infrastructure used by multiple federal agencies. Which NIST document specifically guides security for such multi-tenant environments under the federal authorization process?

    Answer: FedRAMP Authorization Framework

    FedRAMP provides a standardized approach to security assessment and authorization for cloud services used by federal agencies.

  2. Which type of authentication token generates a one-time password synchronized to a time-based algorithm, satisfying the AAL2 requirement under NIST SP 800-63B?

    Answer: TOTP hardware token

    TOTP hardware tokens are phishing-resistant single-factor cryptographic devices that meet NIST 800-63B AAL2 requirements.

  3. When reviewing an access control list, a CAP professional notices a terminated employee still has active credentials. Which principle was violated?

    Answer: Timely account deprovisioning (least privilege lifecycle)

    Failing to disable accounts promptly after employment termination violates the account lifecycle management aspect of least privilege.

  4. In a zero-trust architecture, what replaces network location as the primary basis for access decisions?

    Answer: Continuous verification of identity, device health, and context

    Zero trust requires continuous validation of user identity, device posture, and contextual signals before granting access, regardless of network location.

  5. An organization uses attribute-based access control where a policy states 'grant access if user.clearance >= data.classification AND user.project == data.project.' This policy is evaluated by which component?

    Answer: Policy Decision Point (PDP)

    The PDP evaluates access requests against policies and returns permit or deny decisions to the PEP.

  6. Which NIST SP 800-53 control requires organizations to review accounts at defined frequencies to confirm access remains appropriate?

    Answer: AC-2(j) – Account Review

    AC-2(j) requires periodic review of information system accounts to verify continued need and appropriate access levels.

  7. A system requires that no single administrator can both create user accounts AND assign elevated privileges. This enforces which security principle?

    Answer: Separation of duties

    Separation of duties splits sensitive tasks between multiple individuals to prevent any one person from having unchecked control.