← All CAP Flashcard Decks

Identity & Access Management Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity & Access Management flashcards as text
  1. Under FIPS 201, PIV credentials issued to federal employees must support which minimum number of authentication factors when accessing high-value assets?

    Answer: Two factors (card + PIN)

    FIPS 201 PIV requires at minimum two-factor authentication combining physical card possession with a PIN for logical access.

  2. A CAP professional is assessing a system where user A can grant other users permissions that exceed user A's own permissions. Which access control weakness does this represent?

    Answer: Privilege escalation via DAC misconfiguration

    In DAC environments, improper implementation can allow owners to delegate permissions they do not actually possess, enabling privilege escalation.

  3. Which NIST SP 800-53 control enhancement specifically requires cryptographic replay-resistant authentication mechanisms?

    Answer: IA-2(8)

    IA-2(8) requires network access for privileged accounts to use replay-resistant authentication mechanisms such as PKI or OTP.

  4. An organization implements Just-in-Time (JIT) privileged access, where elevated rights are granted only for the duration of an approved task. This practice primarily supports which security principle?

    Answer: Least privilege

    JIT access directly implements least privilege by ensuring elevated rights exist only as long as operationally necessary.

  5. When a federal system uses SAML 2.0 for single sign-on, the component that makes assertions about user identity to the service provider is called what?

    Answer: Identity Provider (IdP)

    The Identity Provider authenticates the user and issues SAML assertions containing identity and attribute claims to the Service Provider.

  6. A security assessment reveals that accounts for contractors are not disabled within 24 hours of contract expiration. Under NIST SP 800-53, which control is not being met?

    Answer: AC-2 – Account Management

    AC-2 requires organizations to manage accounts throughout their lifecycle, including timely deactivation upon contract completion or personnel departure.

  7. Which authentication assurance level under NIST SP 800-63B permits the use of memorized secrets (passwords) alone as an acceptable authenticator for low-risk applications?

    Answer: AAL1

    AAL1 requires at minimum single-factor authentication and permits the use of a memorized secret (password) as the sole authenticator.