โ† All CCP Flashcard Decks

IAM & Multi-Factor Authentication Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IAM & Multi-Factor Authentication flashcards as text
  1. What is the purpose of an IAM access review (also called a recertification campaign)?

    Answer: To periodically verify that user access rights remain appropriate and remove unnecessary privileges

    Access reviews ensure accumulated privileges are recertified by managers or owners, supporting least privilege by removing access that is no longer needed.

  2. Which attack exploits the trust relationship between a user's browser and a web application to perform unauthorized actions using the user's authenticated session?

    Answer: Cross-Site Request Forgery (CSRF)

    CSRF tricks an authenticated user's browser into sending forged requests to a trusted site, leveraging the existing session cookie to perform unauthorized actions.

  3. In OAuth 2.0, what does the 'scope' parameter control?

    Answer: The specific permissions and resources the access token grants

    Scopes define the level of access requested by the client, limiting what actions the access token permits on the resource server.

  4. What is 'privilege creep' in IAM?

    Answer: The gradual accumulation of excessive access rights as users change roles without deprovisioning old access

    Privilege creep occurs when users accumulate access rights from previous roles without proper deprovisioning, violating the principle of least privilege.

  5. Which MFA enrollment best practice prevents account takeover during the self-service MFA registration process?

    Answer: Requiring users to register MFA before first login using a temporary code sent to a verified channel

    Requiring identity verification (e.g., a code sent to a pre-verified email or phone) before MFA enrollment ensures an attacker cannot register their own MFA device for a victim account.

  6. What is the key difference between authentication and authorization?

    Answer: Authentication verifies who you are; authorization determines what you are allowed to do

    Authentication confirms identity (who you are), while authorization determines permissions (what you can access or do) after identity is established.

  7. A company wants to ensure contractors can only access systems during business hours. Which IAM feature addresses this requirement?

    Answer: Time-based access restrictions in ABAC policies

    ABAC policies can include environmental conditions like time of day, allowing access to be automatically denied outside defined hours.