IAM & Multi-Factor Authentication Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 IAM & Multi-Factor Authentication flashcards as text
What is a 'push notification' MFA attack (also called MFA fatigue)?
Answer: Flooding a user's authenticator app with approval requests hoping the user approves one out of frustration
MFA fatigue attacks bombard users with repeated push authentication requests until the user accidentally or frustratedly approves one, granting attacker access.
Which OpenID Connect component provides verifiable claims about the authenticated user to the client application?
Answer: ID token
The ID token is a JWT issued by the OpenID Provider containing claims about the authenticated user (e.g., sub, email) that the client can verify.
What is the purpose of a Privileged Access Workstation (PAW)?
Answer: A dedicated, hardened system used exclusively for privileged administrative tasks to reduce exposure
PAWs are dedicated hardened workstations used only for privileged tasks, preventing credential theft through phishing or malware that could occur on general-purpose machines.
In SAML 2.0, what is the function of the XML signature on an assertion?
Answer: It ensures integrity and authenticity, proving the assertion was issued by the trusted IdP and not tampered with
The XML digital signature on a SAML assertion allows the Service Provider to verify that the assertion was created by the trusted IdP and has not been modified in transit.
Which concept describes the ability to verify that a specific user performed a specific action, preventing them from later denying it?
Answer: Non-repudiation
Non-repudiation uses mechanisms like digital signatures and audit logs to ensure a user cannot deny having performed an action.
What risk does 'shadow IT' pose to an organization's IAM program?
Answer: Users accessing unsanctioned applications bypass IAM controls, creating ungoverned access and credential exposure
Shadow IT creates accounts and access outside of IT governance, meaning those accounts are not subject to deprovisioning, MFA enforcement, or access reviews.
Which Kerberos component issues Ticket Granting Tickets (TGTs) after verifying user credentials?
Answer: Key Distribution Center – Authentication Service (KDC-AS)
The Authentication Service (AS) component of the KDC verifies the user's credentials and issues a TGT, which is then used to request service tickets from the TGS.