Identity & Access Management Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity & Access Management flashcards as text
Under FIPS 201, PIV credentials issued to federal employees must support which minimum number of authentication factors when accessing high-value assets?
Answer: Two factors (card + PIN)
FIPS 201 PIV requires at minimum two-factor authentication combining physical card possession with a PIN for logical access.
A CAP professional is assessing a system where user A can grant other users permissions that exceed user A's own permissions. Which access control weakness does this represent?
Answer: Privilege escalation via DAC misconfiguration
In DAC environments, improper implementation can allow owners to delegate permissions they do not actually possess, enabling privilege escalation.
Which NIST SP 800-53 control enhancement specifically requires cryptographic replay-resistant authentication mechanisms?
Answer: IA-2(8)
IA-2(8) requires network access for privileged accounts to use replay-resistant authentication mechanisms such as PKI or OTP.
An organization implements Just-in-Time (JIT) privileged access, where elevated rights are granted only for the duration of an approved task. This practice primarily supports which security principle?
Answer: Least privilege
JIT access directly implements least privilege by ensuring elevated rights exist only as long as operationally necessary.
When a federal system uses SAML 2.0 for single sign-on, the component that makes assertions about user identity to the service provider is called what?
Answer: Identity Provider (IdP)
The Identity Provider authenticates the user and issues SAML assertions containing identity and attribute claims to the Service Provider.
A security assessment reveals that accounts for contractors are not disabled within 24 hours of contract expiration. Under NIST SP 800-53, which control is not being met?
Answer: AC-2 – Account Management
AC-2 requires organizations to manage accounts throughout their lifecycle, including timely deactivation upon contract completion or personnel departure.
Which authentication assurance level under NIST SP 800-63B permits the use of memorized secrets (passwords) alone as an acceptable authenticator for low-risk applications?
Answer: AAL1
AAL1 requires at minimum single-factor authentication and permits the use of a memorized secret (password) as the sole authenticator.