Identity & Access Management Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity & Access Management flashcards as text
Under the CAP exam body of knowledge, which activity ensures that access rights granted to users are aligned with current business needs and have not accumulated beyond what is required?
Answer: Access recertification (access review)
Access recertification campaigns periodically validate that user entitlements remain appropriate and remove access that is no longer needed.
A system uses both a hardware token and a biometric scan to authenticate. If an attacker compromises the biometric template database, what compensating control most directly limits the damage?
Answer: Encrypting the biometric templates at rest
Encrypting stored biometric templates prevents attackers from extracting usable reference data even if they gain access to the database.
Which concept allows a cloud consumer to trust a cloud provider's security controls without conducting their own full assessment, based on a shared authorization package?
Answer: Reciprocity
Reciprocity allows agencies to accept another agency's or provider's existing ATO package rather than conducting a redundant assessment.
An identity governance solution automatically flags when a user's role assignments conflict—for example, holding both 'invoice creator' and 'invoice approver' roles. This is an example of which IAM capability?
Answer: Segregation of duties (SoD) conflict detection
SoD conflict detection identifies role combinations that violate separation of duties policies, preventing a single user from having incompatible privileges.
Under NIST SP 800-53 control IA-5, which authenticator management requirement specifically addresses the minimum complexity and lifetime of passwords?
Answer: IA-5(1) – Password-Based Authentication
IA-5(1) defines requirements for password complexity, history, minimum/maximum lifetimes, and reuse restrictions.
When a user authenticates to a web application and receives a session token, which attack exploits the failure to invalidate that token after the user logs out?
Answer: Session hijacking via token reuse
If session tokens remain valid after logout, an attacker who captured the token can reuse it to impersonate the user.
A CAP candidate is reviewing a continuous monitoring plan. Which metric best indicates the health of the identity and access management program over time?
Answer: Percentage of accounts reviewed and recertified within defined timeframes
Tracking recertification completion rates directly measures how well the organization maintains appropriate access controls over time.