Identity & Access Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity & Access Management flashcards as text
What is the primary objective of an Identity and Access Management (IAM) program within an enterprise?
Answer: Ensuring the right individuals access the right resources at the right times for the right reasons
IAM programs are designed to ensure appropriate access by verified identities to authorized resources, balancing security with operational efficiency.
Which access control model assigns permissions based on an individual's job function or title within an organization?
Answer: Role-Based Access Control (RBAC)
RBAC grants access rights based on defined roles, making it easier to manage permissions at scale by mapping users to roles rather than assigning individual rights.
The principle of least privilege in IAM requires that users be granted:
Answer: Access only to the resources and data necessary to perform their assigned job functions
Least privilege minimizes the attack surface by limiting user permissions to only what is required for their specific role, reducing risk from insider threats and compromised accounts.
Which authentication factor category includes biometric methods such as fingerprints and retinal scans?
Answer: Something you are
Biometric factors fall under 'something you are' because they are inherent physical or behavioral characteristics unique to the individual.
What is the primary security benefit of implementing Single Sign-On (SSO) in an enterprise environment?
Answer: It reduces password fatigue and the risk of weak or reused passwords across multiple applications
SSO allows users to authenticate once and access multiple applications, reducing the number of passwords users must manage and lowering the risk of weak or reused credentials.
What is the purpose of conducting periodic user access reviews or access recertification campaigns?
Answer: To ensure that user access rights remain appropriate and remove access that is no longer needed
Access recertification ensures that access rights are valid and current, preventing accumulation of excessive privileges (access creep) over time.
A Privileged Access Workstation (PAW) is primarily used to:
Answer: Perform high-risk administrative tasks in an isolated, hardened environment
A PAW is a dedicated, hardened workstation used exclusively for sensitive administrative tasks to reduce the risk of compromise from malware or phishing attacks on standard workstations.