โ† All CCP Flashcard Decks

IAM & Multi-Factor Authentication Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IAM & Multi-Factor Authentication flashcards as text
  1. What is the primary purpose of a Privileged Identity Management (PIM) solution?

    Answer: To provide on-demand, time-limited elevation of privileged access with full audit trails

    PIM solutions like Azure AD PIM enable just-in-time privileged access, requiring approval and time-bounding elevated rights to minimize standing privilege exposure.

  2. An attacker captures a valid SAML assertion during transmission. What attack could they attempt?

    Answer: Replay the stolen assertion to gain unauthorized access to the Service Provider

    Without proper short validity windows and assertion ID tracking, a captured SAML assertion can be replayed to authenticate as the victim at the Service Provider.

  3. Which IAM concept ensures that no single individual has end-to-end control over a critical process, requiring multiple people to complete sensitive tasks?

    Answer: Separation of duties (SoD)

    Separation of duties requires that critical processes involve multiple individuals, preventing fraud or error by ensuring no one person can complete a sensitive transaction alone.

  4. What is 'continuous authentication' in modern IAM?

    Answer: Ongoing risk-based verification of user identity throughout a session using behavioral signals

    Continuous authentication monitors behavioral signals (typing patterns, mouse movement, location) throughout a session and triggers re-authentication if risk indicators change.

  5. In Zero Trust Architecture, what does 'never trust, always verify' mean for IAM?

    Answer: Every access request must be authenticated and authorized regardless of network location or prior session

    Zero Trust eliminates implicit trust based on network location; every request requires explicit identity verification, device health validation, and authorization before access is granted.

  6. Which biometric authentication factor is classified as 'something you are' and is considered an inherence factor?

    Answer: Fingerprint scan

    Fingerprint scans are biometric inherence factors ('something you are') because they measure a unique physical characteristic of the user.

  7. What is the security advantage of using short-lived access tokens in OAuth 2.0 over long-lived session cookies?

    Answer: If a token is stolen, its value expires quickly, limiting the attacker's window of exploitation

    Short-lived access tokens limit the damage from token theft because the stolen credential becomes useless after expiration, typically within minutes to an hour.