IAM & Multi-Factor Authentication Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IAM & Multi-Factor Authentication flashcards as text
What is the primary purpose of a Privileged Identity Management (PIM) solution?
Answer: To provide on-demand, time-limited elevation of privileged access with full audit trails
PIM solutions like Azure AD PIM enable just-in-time privileged access, requiring approval and time-bounding elevated rights to minimize standing privilege exposure.
An attacker captures a valid SAML assertion during transmission. What attack could they attempt?
Answer: Replay the stolen assertion to gain unauthorized access to the Service Provider
Without proper short validity windows and assertion ID tracking, a captured SAML assertion can be replayed to authenticate as the victim at the Service Provider.
Which IAM concept ensures that no single individual has end-to-end control over a critical process, requiring multiple people to complete sensitive tasks?
Answer: Separation of duties (SoD)
Separation of duties requires that critical processes involve multiple individuals, preventing fraud or error by ensuring no one person can complete a sensitive transaction alone.
What is 'continuous authentication' in modern IAM?
Answer: Ongoing risk-based verification of user identity throughout a session using behavioral signals
Continuous authentication monitors behavioral signals (typing patterns, mouse movement, location) throughout a session and triggers re-authentication if risk indicators change.
In Zero Trust Architecture, what does 'never trust, always verify' mean for IAM?
Answer: Every access request must be authenticated and authorized regardless of network location or prior session
Zero Trust eliminates implicit trust based on network location; every request requires explicit identity verification, device health validation, and authorization before access is granted.
Which biometric authentication factor is classified as 'something you are' and is considered an inherence factor?
Answer: Fingerprint scan
Fingerprint scans are biometric inherence factors ('something you are') because they measure a unique physical characteristic of the user.
What is the security advantage of using short-lived access tokens in OAuth 2.0 over long-lived session cookies?
Answer: If a token is stolen, its value expires quickly, limiting the attacker's window of exploitation
Short-lived access tokens limit the damage from token theft because the stolen credential becomes useless after expiration, typically within minutes to an hour.