← All CCSK Flashcard Decks

Identity and Access Management in Cloud Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Identity and Access Management in Cloud flashcards as text
  1. What is 'identity sprawl' in cloud environments and why is it a security concern?

    Answer: The proliferation of unmanaged identities across multiple cloud services, creating governance blind spots

    Identity sprawl occurs when identities multiply across cloud services without central governance, making it difficult to track, manage, and revoke access.

  2. According to CCSK, what is the significance of the 'principle of least privilege' in cloud IAM?

    Answer: Users should only receive the minimum access necessary to perform their job functions

    Least privilege limits the potential damage of compromised credentials by ensuring each identity has only the permissions needed for its specific tasks.

  3. What is 'OAuth 2.0' and how is it relevant to CCSK cloud security?

    Answer: An authorization framework that allows third-party applications to access resources on behalf of users without exposing credentials

    OAuth 2.0 enables delegated authorization — applications obtain scoped access tokens without the user's credentials being shared with the third party.

  4. What is 'SAML' and what role does it play in cloud federated identity?

    Answer: Security Assertion Markup Language; it enables SSO by passing authentication assertions between identity and service providers

    SAML is an XML-based standard for exchanging authentication and authorization data, enabling single sign-on between an identity provider and cloud service providers.

  5. In CCSK, what is the recommended practice for managing dormant or unused cloud accounts?

    Answer: Regularly audit and disable or delete accounts that have been inactive beyond a defined threshold

    Dormant accounts represent unnecessary risk; regular access reviews and removal of unused accounts reduces the attack surface.

  6. What is a 'permission boundary' in cloud IAM and how does it support security?

    Answer: A policy that sets the maximum permissions an identity can receive, regardless of other policies attached

    Permission boundaries cap the maximum effective permissions for an identity, preventing privilege escalation even if other permissive policies are attached.