CCP Identity & Access Management Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCP Identity & Access Management flashcards as text
Which type of attack exploits the trust between a service provider and an identity provider by injecting a forged SAML assertion?
Answer: SAML injection
SAML injection attacks craft or modify SAML assertions to impersonate a privileged user, bypassing authentication controls at the service provider.
What is 'role explosion' in the context of RBAC, and why is it a security concern?
Answer: An unmanageable proliferation of roles that makes access reviews difficult and increases the risk of excessive privilege
Role explosion occurs when organizations create too many granular roles, making it nearly impossible to audit entitlements and increasing the likelihood of privilege creep.
An attacker steals a Kerberos Ticket Granting Ticket (TGT) for a domain administrator. What attack technique does this enable?
Answer: Pass-the-ticket
Pass-the-ticket allows an attacker to use a stolen Kerberos TGT to authenticate as the victim user without knowing the actual password.
Which US federal directive mandates that agencies implement phishing-resistant MFA and zero trust architecture as part of their cybersecurity improvement?
Answer: Executive Order 14028
Executive Order 14028 (Improving the Nation's Cybersecurity, May 2021) requires federal agencies to adopt MFA, encryption, and zero trust architecture.
What is the difference between authentication and authorization in the context of IAM?
Answer: Authentication confirms identity; authorization determines what an authenticated user is permitted to do
Authentication verifies 'who you are,' while authorization enforces 'what you are allowed to do' after identity has been confirmed.
Which IAM process ensures that user access rights are periodically reviewed and certified by data owners or managers?
Answer: Access certification (access review)
Access certification requires managers or data owners to formally review and approve or revoke user entitlements on a scheduled basis to prevent privilege creep.