CIAM – Certified Identity and Access Manager — Questions and Answers
Question 1: A company processing EU citizen data from a U.S. data center must rely on which mechanism to legally transfer data under GDPR?
- EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) (Correct answer)
- A signed NDA with the data processor
- ISO 27001 certification of the U.S. facility
- GDPR Article 9 explicit consent only
Correct answer: EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs)
International data transfers from the EU to the U.S. require a valid transfer mechanism such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
Question 2: Which type of risk assessment uses numerical values and statistical models to quantify potential losses?
- Residual risk assessment
- Inherent risk assessment
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
Correct answer: Quantitative risk assessment
Quantitative risk assessments use financial metrics like Annual Loss Expectancy (ALE) to express risk in monetary terms.
Question 3: Which component of the NIST Cybersecurity Framework (CSF) specifically addresses the ability to detect the occurrence of a cybersecurity event?
- Protect
- Detect (Correct answer)
- Respond
- Identify
Correct answer: Detect
The Detect function in the NIST CSF defines activities for timely discovery of cybersecurity events, including continuous monitoring and anomaly detection.
Question 4: What is the purpose of a 'tabletop exercise' in the context of CIAM incident response planning?
- To review and update user access permissions
- To simulate a security incident scenario and walk through response procedures verbally (Correct answer)
- To perform live penetration testing on the CIAM platform
- To physically test network failover hardware
Correct answer: To simulate a security incident scenario and walk through response procedures verbally
A tabletop exercise is a discussion-based simulation where participants talk through their response to a hypothetical incident without real-world execution.
Question 5: What is the significance of 'time-stamping' in IAM audit logs?
- It controls when access certification campaigns are triggered
- It determines user session timeout intervals
- It manages password expiration schedules
- It establishes the sequence and timing of events, which is critical for forensic investigation and compliance (Correct answer)
Correct answer: It establishes the sequence and timing of events, which is critical for forensic investigation and compliance
Accurate timestamps in audit logs establish the precise sequence of events, which is essential for reconstructing incidents, proving compliance, and correlating events across systems.
Question 6: What is 'privileged user monitoring'?
- Monitoring only non-administrative standard users
- A password complexity monitoring tool for admin accounts
- Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts (Correct answer)
- Network-level monitoring of privileged user workstations
Correct answer: Enhanced logging, session recording, and alerting for actions taken by administrative and privileged accounts
Privileged user monitoring implements heightened audit controls including comprehensive logging, session recording, and real-time alerting specifically for high-privilege accounts.
Question 7: Which control helps prevent 'ghost accounts'—active accounts belonging to users who have left the organization?
- Mandatory password rotation every 30 days
- IP allowlisting for all enterprise applications
- Single sign-on enforcement
- Periodic access reconciliation against the HR system (Correct answer)
Correct answer: Periodic access reconciliation against the HR system
Reconciling the IAM directory against the authoritative HR system on a scheduled basis detects accounts that should have been deprovisioned but weren't.
Question 8: A 'ghost account' in IAM governance terminology refers to:
- An account created for testing that was never deleted
- A service account with no assigned owner
- An active account belonging to a user who no longer exists in the HR system (Correct answer)
- A shared account used by multiple administrators
Correct answer: An active account belonging to a user who no longer exists in the HR system
Ghost (or orphan) accounts are active user accounts that remain in the system after the associated employee has left, posing a significant security and compliance risk.
Question 9: What does WS-Federation stand for?
- Web Standard Federation
- Web Services Federation (Correct answer)
- Workstation Security Federation
- Wide-Scale Federation
Correct answer: Web Services Federation
WS-Federation (Web Services Federation) is a Microsoft-developed protocol that enables identity and security information sharing across different security domains.
Question 10: A company must prove that terminated employees lose system access within 24 hours. Which compliance activity best demonstrates this?
- User access recertification campaign
- Joiner-mover-leaver process audit log review (Correct answer)
- Vulnerability scan report
- Firewall rule review
Correct answer: Joiner-mover-leaver process audit log review
Reviewing joiner-mover-leaver (JML) process audit logs shows the timestamps of deprovisioning actions relative to termination events.
Question 11: What is phishing?
- A type of firewall
- A network scanning tool
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
- A backup system
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 12: What is multi-factor authentication (MFA)?
- Having multiple accounts
- Requiring two or more verification methods to confirm identity (Correct answer)
- Logging in from multiple devices
- Using multiple passwords
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 13: In identity governance, what is the risk of 'orphaned accounts'?
- They cause duplicate identity records in the directory
- They consume unnecessary software licenses only
- They prevent new accounts from being created
- They provide a persistent attack surface since no owner monitors or manages them (Correct answer)
Correct answer: They provide a persistent attack surface since no owner monitors or manages them
Orphaned accounts belong to departed employees or decommissioned systems and remain active without oversight, making them prime targets for attackers.
Question 14: In ABAC, what is a 'policy information point' (PIP) responsible for?
- Enforcing the access decision at the resource
- Storing and managing authorization policies
- Logging and auditing access decisions for compliance
- Retrieving attribute values needed to evaluate a policy (Correct answer)
Correct answer: Retrieving attribute values needed to evaluate a policy
The Policy Information Point (PIP) retrieves attribute values (user, resource, or environmental) from external sources such as LDAP, databases, or APIs to support policy evaluation.
Question 15: What is the purpose of the 'entryTTL' operational attribute in an LDAP directory?
- Defines the maximum time a cached LDAP query result is considered valid
- Specifies the remaining time-to-live for a dynamically created directory entry (Correct answer)
- Controls the session timeout for an authenticated LDAP connection
- Sets the replication delay for the entry across directory replicas
Correct answer: Specifies the remaining time-to-live for a dynamically created directory entry
entryTTL is used with dynamic entries (RFC 2589) to specify how many seconds remain before the entry expires and is automatically deleted by the server.
Question 16: Which control specifically prevents a privileged user from reading their own audit logs within a PAM system?
- Separation of duties (Correct answer)
- Need-to-know
- Least privilege
- Dual control
Correct answer: Separation of duties
Separation of duties ensures that the person performing privileged actions is different from the person who audits those actions.
Question 17: What is the primary purpose of maintaining an identity audit trail throughout the lifecycle?
- To optimize provisioning performance by caching prior states
- To provide accountability and evidence for compliance investigations (Correct answer)
- To enable faster password resets for support teams
- To allow users to review their own access history
Correct answer: To provide accountability and evidence for compliance investigations
An identity audit trail records all lifecycle events—creation, modification, access grants, and deletion—to support compliance, forensic investigations, and accountability.
Question 18: Which IAM technology is primarily used to manage access to network resources such as VPNs and Wi-Fi using a centralized authentication protocol?
- RADIUS (Correct answer)
- SAML 2.0
- WS-Trust
- SCIM
Correct answer: RADIUS
RADIUS (Remote Authentication Dial-In User Service) is widely used to authenticate network access requests for VPNs, Wi-Fi, and network equipment.
Question 19: In the context of IAM, what is the key security benefit of using hardware security keys (e.g., YubiKey) over SMS-based OTP?
- Hardware keys are cheaper to deploy
- Hardware keys work without an internet connection only
- Hardware keys do not require enrollment
- Hardware keys are immune to SIM-swapping and phishing attacks (Correct answer)
Correct answer: Hardware keys are immune to SIM-swapping and phishing attacks
Hardware security keys are phishing-resistant because they use origin-bound cryptographic challenges, and they cannot be compromised by SIM-swapping attacks that target SMS OTP.
Question 20: In a DAC system, who ultimately controls access to a resource?
- The security policy engine
- The mandatory security label
- The resource owner (Correct answer)
- The system administrator exclusively
Correct answer: The resource owner
In DAC, the owner of a resource has discretion to grant or revoke access to other users, unlike MAC where the system enforces access centrally.
Question 21: Which protocol does Azure AD Connect use to synchronize identities from on-premises Active Directory to Azure AD?
- SAML 2.0
- Microsoft Identity Integration Server protocol with AAD Sync rules (Correct answer)
- OAuth 2.0
- SCIM 2.0
Correct answer: Microsoft Identity Integration Server protocol with AAD Sync rules
Azure AD Connect uses its own synchronization engine with configurable sync rules to replicate objects from on-premises AD to Azure AD via the Microsoft sync protocol.
Question 22: In certificate-based authentication, what cryptographic artifact does the client present to prove identity?
- A digital certificate containing the client's public key (Correct answer)
- A session cookie signed by the server
- A SAML assertion from the IdP
- A hashed copy of the client's password
Correct answer: A digital certificate containing the client's public key
Certificate-based authentication requires the client to present a digital certificate (e.g., X.509) containing its public key, signed by a trusted Certificate Authority.
Question 23: What protocol is commonly used for federated identity management to exchange authentication and authorization data between parties?
- LDAP
- RADIUS
- SAML (Correct answer)
- SNMP
Correct answer: SAML
SAML (Security Assertion Markup Language) is the standard XML-based protocol for exchanging authentication and authorization data in federated identity systems.
Question 24: In identity lifecycle management, what is a 'role explosion' risk?
- Duplicate role definitions across multiple connected applications
- An unmanageable proliferation of fine-grained roles that increases complexity (Correct answer)
- Rapid growth in the number of user accounts beyond system capacity
- A security incident caused by overly broad role assignments
Correct answer: An unmanageable proliferation of fine-grained roles that increases complexity
Role explosion occurs when organizations create too many granular roles, making role management, assignment, and certification unmanageable.
Question 25: In OAuth 2.0, which grant type is most appropriate for a server-to-server integration where no user is involved?
- Resource Owner Password Credentials
- Client Credentials (Correct answer)
- Implicit
- Authorization Code
Correct answer: Client Credentials
The Client Credentials grant is used for machine-to-machine communication where the application authenticates with its own client ID and secret, without a user context.
Question 26: In the Biba Integrity Model, the 'no write up' property means that a subject:
- Cannot modify its own security label
- Cannot write to objects at a higher integrity level (Correct answer)
- Cannot execute programs at any integrity level
- Cannot read objects at a lower integrity level
Correct answer: Cannot write to objects at a higher integrity level
In Biba, subjects cannot write to objects at higher integrity levels to prevent corrupting trusted data with less-trusted data.
Question 27: Which NIST Special Publication specifically provides guidelines for digital identity proofing and enrollment?
- NIST SP 800-63A (Correct answer)
- NIST SP 800-171
- NIST SP 800-37
- NIST SP 800-53
Correct answer: NIST SP 800-63A
NIST SP 800-63A specifically addresses enrollment and identity proofing, defining the processes and requirements for each Identity Assurance Level.
Question 28: What is the CIA triad in information security?
- Cybersecurity Infrastructure Act
- Confidentiality, Integrity, Availability (Correct answer)
- Certified Information Auditor
- Central Intelligence Agency
Correct answer: Confidentiality, Integrity, Availability
The CIA triad represents three core security principles: Confidentiality (keeping data private), Integrity (data accuracy), Availability (systems accessible when needed).
Question 29: The Chinese Wall Model is primarily designed to prevent:
- Privilege escalation attacks
- Unauthorized data deletion
- Conflicts of interest between competing organizations (Correct answer)
- Insider threats from disgruntled employees
Correct answer: Conflicts of interest between competing organizations
The Chinese Wall (Brewer-Nash) Model prevents consultants from accessing data from competing companies by dynamically restricting access based on prior accesses.
Question 30: A developer is building a mobile app and needs to authenticate users without storing a client secret on the device. Which OAuth 2.0 flow is most appropriate?
- Resource Owner Password Credentials flow
- Implicit flow
- Authorization Code flow with PKCE (Correct answer)
- Client Credentials flow
Correct answer: Authorization Code flow with PKCE
Authorization Code with PKCE is designed for public clients (mobile and SPA apps) that cannot securely store a client secret, using a dynamically generated code verifier instead.
Question 31: What does 'operational attribute' mean in LDAP terminology?
- An attribute required by all object classes in the schema
- An attribute used to link two entries through a referential integrity constraint
- An attribute that triggers server-side business logic when modified
- An attribute maintained by the server (e.g., createTimestamp) not returned unless explicitly requested (Correct answer)
Correct answer: An attribute maintained by the server (e.g., createTimestamp) not returned unless explicitly requested
Operational attributes like createTimestamp, modifyTimestamp, and entryUUID are maintained automatically by the server and are not included in search results unless specifically requested with '+'.
Question 32: An organization wants to verify that its CIAM security controls are working as designed. Which activity BEST accomplishes this?
- Reviewing vendor documentation
- Redeploying the CIAM platform
- Conducting a security control assessment or audit (Correct answer)
- Updating user account passwords
Correct answer: Conducting a security control assessment or audit
A security control assessment validates that implemented controls are operating effectively and meeting their intended objectives.
Question 33: An attacker exploits a Kerberos vulnerability to forge tickets granting domain admin access. What is this attack called?
- Silver ticket attack
- Golden ticket attack (Correct answer)
- Pass-the-ticket
- AS-REP roasting
Correct answer: Golden ticket attack
A golden ticket attack forges Kerberos TGTs using the krbtgt account hash, granting persistent domain admin access.
Question 34: What is 'scope downscoping' in OAuth 2.0 token exchange (RFC 8693)?
- Requesting scopes that exceed the client's registered permissions
- Issuing a new token with a reduced set of scopes from the original token (Correct answer)
- Automatically expanding scopes when access tokens are refreshed
- Removing expired scopes from the authorization server's policy
Correct answer: Issuing a new token with a reduced set of scopes from the original token
Scope downscoping in token exchange means the newly issued token has fewer or more restricted scopes than the original token, applying least-privilege for specific delegated operations.
Question 35: A SOC 2 Type II report differs from SOC 2 Type I primarily in that it:
- Requires third-party penetration testing
- Covers additional trust service criteria
- Evaluates controls over a period of time rather than a point in time (Correct answer)
- Is intended for regulatory bodies rather than customers
Correct answer: Evaluates controls over a period of time rather than a point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (typically 6–12 months), while Type I assesses design at a single point in time.
Question 36: A company's IGA audit reveals that 40% of certifications were approved in under 10 seconds. What does this most likely indicate?
- The access rights are all low-risk and trivial to certify
- The IGA system is performing efficiently
- Reviewers are rubber-stamping approvals without due diligence (Correct answer)
- Automated certification bots completed the reviews
Correct answer: Reviewers are rubber-stamping approvals without due diligence
Extremely fast approval times across many certifications are a strong indicator of rubber-stamping, where reviewers click approve without meaningful review of the entitlements.
Question 37: Which proofing method allows IAL3-equivalent remote identity proofing using a live video call with a trained operator?
- Knowledge-based remote proofing
- Self-service remote proofing
- Supervised remote proofing (Correct answer)
- Federated identity proofing
Correct answer: Supervised remote proofing
Supervised remote proofing uses a live, real-time video session monitored by a trained operator who can examine documents, capture biometrics, and interact with the applicant to meet IAL3 requirements without physical presence.
Question 38: What is the purpose of the 'nonce' parameter in OpenID Connect authorization requests?
- To prevent CSRF attacks on the redirect URI
- To specify the number of authentication factors required
- To request a specific token lifetime from the authorization server
- To bind the ID token to the client session and prevent token replay (Correct answer)
Correct answer: To bind the ID token to the client session and prevent token replay
The nonce is a random value included in the authorization request and embedded in the resulting ID token, allowing the client to verify the token was issued for its specific session.
Question 39: Why is continuing education important in Authorization Frameworks?
- To network only
- To stay current with evolving standards and practices (Correct answer)
- Only for re-certification requirements
- It is not important after certification
Correct answer: To stay current with evolving standards and practices
Continuing education keeps professionals updated with the latest developments, standards, and best practices in their field.
Question 40: What is the difference between authentication logging and authorization logging?
- Authorization logging records password changes while authentication logging records role assignments
- There is no meaningful difference between the two types
- Authentication logging is encrypted while authorization logging is stored in plain text
- Authentication logging records identity verification events; authorization logging records access control decisions (Correct answer)
Correct answer: Authentication logging records identity verification events; authorization logging records access control decisions
Authentication logging captures login and logout events that verify identity, while authorization logging records access control decisions — what resources were allowed or denied to authenticated users.
Question 41: Which principle in the FAIR (Factor Analysis of Information Risk) model represents the probable frequency of a threat event occurring?
- Loss magnitude
- Risk
- Threat event frequency (Correct answer)
- Vulnerability
Correct answer: Threat event frequency
Threat Event Frequency (TEF) in the FAIR model quantifies how often a threat agent is likely to act against an asset over a given time period.
Question 42: Which of the following is a key factor in ensuring compliance with privacy regulations such as GDPR in IAM?
- Implementing strong password policies
- Using MFA for all users
- Encrypting user data during storage and transmission (Correct answer)
- Enabling SSO for all systems
Correct answer: Encrypting user data during storage and transmission
Encrypting user data, both when it is stored (at rest) and when it is being transmitted, is a critical measure for protecting personal information. This practice helps ensure compliance with privacy regulations like GDPR by safeguarding sensitive data from unauthorized access and breaches.
Question 43: What is 'orphan account' detection in IAM?
- Identifying active accounts that remain after the associated employee has left or changed roles (Correct answer)
- Detecting anonymous guest accounts in directory services
- Finding shared service accounts with no designated owner
- Finding user accounts that lack assigned passwords
Correct answer: Identifying active accounts that remain after the associated employee has left or changed roles
Orphan account detection identifies accounts that remain enabled after the associated user has been terminated or transferred, reducing the attack surface from stale credentials.
Question 44: A CIAM administrator discovers that a third-party identity provider (IdP) has suffered a breach. What is the FIRST step to take?
- Shut down the entire CIAM platform
- Notify all end users immediately
- Revoke or invalidate all active sessions and tokens issued by that IdP (Correct answer)
- Conduct a penetration test
Correct answer: Revoke or invalidate all active sessions and tokens issued by that IdP
Revoking active sessions and tokens from the compromised IdP immediately stops attackers from leveraging stolen credentials.
Question 45: In a GDPR context, what is the maximum timeframe for notifying supervisory authorities after discovering a personal data breach?
- 7 days
- 48 hours
- 24 hours
- 72 hours (Correct answer)
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 46: Which cloud-native feature in AWS allows services to assume a role with temporary credentials instead of using long-term access keys?
- IAM roles with STS (Correct answer)
- AWS Organizations SCPs
- IAM groups
- AWS Cognito user pools
Correct answer: IAM roles with STS
AWS IAM roles combined with the Security Token Service (STS) provide temporary, automatically rotated credentials, eliminating long-term static keys.
Question 47: What is the primary difference between authentication and authorization in an IAM system?
- Authentication determines what resources a user can access; authorization verifies who they are
- Authentication verifies the identity of a user; authorization determines what actions they are permitted to perform (Correct answer)
- Authentication is only performed once per day; authorization happens on every request
- Authentication and authorization are interchangeable terms in modern IAM
Correct answer: Authentication verifies the identity of a user; authorization determines what actions they are permitted to perform
Authentication answers 'Who are you?' by verifying identity credentials, while authorization answers 'What are you allowed to do?' by enforcing access control policies.
Question 48: What is the purpose of access certification campaigns?
- Issuing digital identity certificates to new employees
- Periodically verifying that users retain only appropriate access rights by having managers review and approve (Correct answer)
- Certifying IAM administrators through formal examinations
- Testing IAM system performance under peak load conditions
Correct answer: Periodically verifying that users retain only appropriate access rights by having managers review and approve
Access certification campaigns periodically require managers or system owners to review and confirm that each user's access rights remain appropriate for their current role.
Question 49: What is the default port for LDAPS (LDAP over SSL/TLS)?
- 389
- 636 (Correct answer)
- 3269
- 3268
Correct answer: 636
LDAPS uses TCP port 636 for standard domain connections, while port 3269 is used for LDAPS connections to the Global Catalog.
Question 50: Which NIST SP 800-53 control family directly governs identification and authentication requirements?
- CM – Configuration Management
- IA – Identification and Authentication (Correct answer)
- AC – Access Control
- AU – Audit and Accountability
Correct answer: IA – Identification and Authentication
The IA control family in NIST SP 800-53 covers organizational identification and authentication policies, including multi-factor authentication.
Question 51: Which access control model would be MOST appropriate for a government system that must enforce strict information classification and cannot allow users to override access decisions?
- Discretionary Access Control
- Attribute-Based Access Control
- Role-Based Access Control
- Mandatory Access Control (Correct answer)
Correct answer: Mandatory Access Control
MAC is mandated by the system, not individual owners, making it ideal for environments where classification policy must be enforced uniformly and cannot be overridden.
Question 52: Which compliance requirement is primarily satisfied by implementing privileged access workstations (PAWs) for administrators?
- Data residency enforcement
- End-user password complexity
- Privileged account isolation and protection (e.g., NIST SP 800-53 AC-6) (Correct answer)
- Network segmentation for PCI
Correct answer: Privileged account isolation and protection (e.g., NIST SP 800-53 AC-6)
PAWs satisfy privileged access isolation requirements by providing a dedicated, hardened environment for administrative tasks, aligning with NIST AC-6 and similar controls.
Question 53: What is the CIA triad in information security?
- Certified Information Auditor
- Central Intelligence Agency
- Confidentiality, Integrity, Availability (Correct answer)
- Cybersecurity Infrastructure Act
Correct answer: Confidentiality, Integrity, Availability
The CIA triad represents three core security principles: Confidentiality (keeping data private), Integrity (data accuracy), Availability (systems accessible when needed).
Question 54: What does 'log integrity' mean in IAM auditing?
- Ensuring audit logs are human-readable and well-formatted
- Synchronizing log timestamps across distributed systems
- Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness (Correct answer)
- Compressing log files to reduce storage requirements
Correct answer: Protecting audit records from modification or deletion to preserve their evidentiary trustworthiness
Log integrity ensures audit records cannot be altered after creation, typically enforced through cryptographic controls, write-once storage, or tamper-evident log chains.
Question 55: Which concept in IAM governance defines the separation of identity lifecycle management responsibilities so no single administrator can create, enable, and assign privileges to an account alone?
- Need to know
- Dual control
- Segregation of duties (Correct answer)
- Mandatory access control
Correct answer: Segregation of duties
Segregation of duties (SoD) splits critical IAM tasks among multiple individuals to prevent fraud and reduce insider threat risk.
Question 56: Which identity lifecycle stage is most critical for preventing 'ghost accounts' that could be exploited after an employee departure?
- Provisioning
- Access recertification
- Authentication
- Deprovisioning (Correct answer)
Correct answer: Deprovisioning
Deprovisioning (offboarding) must promptly disable or delete accounts when users leave to prevent unauthorized post-departure access.
Question 57: A company wants to implement continuous authentication that monitors user behavior throughout a session, not just at login. Which technology approach supports this?
- Static session tokens with long expiry
- Behavioral biometrics and anomaly detection (Correct answer)
- Basic authentication headers on every request
- One-time passwords sent at login only
Correct answer: Behavioral biometrics and anomaly detection
Behavioral biometrics (typing patterns, mouse movements) and ML-based anomaly detection can continuously verify user identity throughout a session beyond the initial login event.
Question 58: What is 'account linking' in federated identity?
- Associating a user's local account with an external identity provider account to enable SSO (Correct answer)
- Connecting multiple authentication devices to one account
- Linking multiple user permissions into a single role
- Connecting bank accounts to a user profile
Correct answer: Associating a user's local account with an external identity provider account to enable SSO
Account linking associates a user's local service account with their external Identity Provider account, enabling SSO without requiring identical usernames across systems.
Question 59: What is the primary purpose of threat analysis in IAM?
- To improve the authentication methods used by the organization
- To identify potential security risks that could compromise access to systems and data (Correct answer)
- To ensure that the network is optimized for performance
- To evaluate the effectiveness of disaster recovery plans
Correct answer: To identify potential security risks that could compromise access to systems and data
The primary purpose of threat analysis in IAM is to proactively identify potential security risks and vulnerabilities that could compromise access to systems and data. By understanding these threats, organizations can develop strategies and controls to mitigate them before they can be exploited.
Question 60: Which attack targets CIAM systems by using large sets of previously stolen username/password pairs to gain unauthorized access?
- Credential stuffing (Correct answer)
- SQL injection
- Man-in-the-middle
- Phishing
Correct answer: Credential stuffing
Credential stuffing automates the testing of breached credential lists against login endpoints to exploit password reuse.
Question 61: What is 'synthetic identity fraud' in the context of identity proofing?
- Replaying captured biometric data to defeat liveness detection
- Using stolen credentials to impersonate an existing individual
- Creating a fictitious identity by combining real and fabricated personally identifiable information (Correct answer)
- Forging physical identity documents for in-person proofing
Correct answer: Creating a fictitious identity by combining real and fabricated personally identifiable information
Synthetic identity fraud involves constructing a fake identity by blending real information (e.g., a legitimate Social Security Number) with fabricated details, making it harder to detect than traditional identity theft.
Question 62: An organization's CIAM platform stores PII for millions of customers. Which regulation primarily governs data breach notification requirements in the United States at the federal level for financial institutions?
- GLBA Safeguards Rule (Correct answer)
- HIPAA Privacy Rule
- GDPR
- CCPA
Correct answer: GLBA Safeguards Rule
The GLBA Safeguards Rule (amended 2023) requires financial institutions to notify the FTC within 30 days of a breach affecting 500+ customers.
Question 63: Which component of a CIAM platform is responsible for managing the user registration and self-service profile update experience?
- Identity Provider (IdP) broker
- Token introspection endpoint
- RADIUS server
- Customer-facing identity portal / self-service UI (Correct answer)
Correct answer: Customer-facing identity portal / self-service UI
The customer-facing identity portal handles self-registration, profile management, and consent collection for end consumers.
Question 64: Which JWT claim specifies the intended audience for the token and should be validated by the recipient?
- jti (JWT ID)
- sub (subject)
- iss (issuer)
- aud (audience) (Correct answer)
Correct answer: aud (audience)
The 'aud' claim identifies the recipients for whom the JWT is intended; recipients must verify that they are included in the audience to prevent token misuse.
Question 65: Which OAuth 2.0 grant type is recommended for machine-to-machine (M2M) authentication where no user is involved?
- Device Authorization
- Implicit
- Client Credentials (Correct answer)
- Authorization Code
Correct answer: Client Credentials
The Client Credentials grant type is designed for server-to-server authentication where the client acts on its own behalf using its own client ID and secret, with no user context.
Question 66: In the context of CIAM, why is LDAP's hierarchical directory structure sometimes less suitable than a flat-schema database for consumer identity storage?
- Consumer identity data is often highly varied and unstructured, fitting poorly into rigid schema-based hierarchies (Correct answer)
- LDAP does not support TLS encryption needed for consumer privacy regulations
- LDAP directories cannot scale beyond one million entries
- LDAP cannot store email addresses or phone numbers required for consumer profiles
Correct answer: Consumer identity data is often highly varied and unstructured, fitting poorly into rigid schema-based hierarchies
Consumer identity attributes vary widely across users and change frequently, which conflicts with the strict, schema-enforced object class model of traditional LDAP directories.
Question 67: What is the primary function of Single Sign-On (SSO)?
- To ensure users can log in with a username and password only once
- To allow users to authenticate using a biometric factor only
- To enable users to sign in to different systems with separate credentials
- To allow multiple systems to authenticate users using one central directory (Correct answer)
Correct answer: To allow multiple systems to authenticate users using one central directory
Single Sign-On (SSO) streamlines the authentication process by allowing users to log in once with a single set of credentials to access multiple independent software systems. This centralizes user authentication, improving convenience and security by reducing the number of passwords users need to manage.
Question 68: A company implements access control where a manager can temporarily grant their permissions to a delegate while on leave. This is an example of:
- Privilege escalation
- Permission delegation (Correct answer)
- Dynamic SSD
- Role inheritance
Correct answer: Permission delegation
Permission delegation allows an authorized user to temporarily transfer a subset of their permissions to another user, common in workflow and identity governance systems.
Question 69: What does 'inherent risk' mean in the context of IAM security assessments?
- The risk accepted by executive leadership
- The risk transferred to a third-party vendor
- The residual risk after all controls are applied
- The risk level before any mitigating controls are in place (Correct answer)
Correct answer: The risk level before any mitigating controls are in place
Inherent risk is the raw or untreated risk exposure that exists before any security controls are implemented.
Question 70: What does 'non-repudiation' mean in the context of IAM auditing?
- Encrypting audit logs to protect their contents
- The ability to refuse an access request
- Preventing unauthorized users from accessing the system
- Ensuring a user cannot deny having performed an authenticated action (Correct answer)
Correct answer: Ensuring a user cannot deny having performed an authenticated action
Non-repudiation ensures that users cannot deny performing actions by providing cryptographically linked evidence tying actions to their authenticated identity.
Question 71: Which of the following best describes 'address of record' verification in identity proofing?
- Checking that a mailing address is formatted correctly
- Confirming a physical or digital address associated with the applicant to establish contact and identity (Correct answer)
- Verifying that a user's IP address matches their registered country
- Validating that an email address is not on a blocklist
Correct answer: Confirming a physical or digital address associated with the applicant to establish contact and identity
Address of record verification confirms a physical or digital address tied to the individual, typically through enrollment codes sent by mail or verified credit bureau records, establishing a real-world connection.
Question 72: In LDAP, what does the 'scope' parameter 'subtree' mean in a search operation?
- Search the base entry and all entries in the subtree below it (Correct answer)
- Search the base entry and its immediate children only
- Search only the base entry specified
- Search all entries in the directory regardless of base
Correct answer: Search the base entry and all entries in the subtree below it
A subtree search returns the base entry and all entries in the entire subtree beneath it, which is the broadest search scope available.
Question 73: Which document formally defines the acceptable use, ownership, and enforcement responsibilities for IAM policies within an organization?
- Business continuity plan
- System security plan
- Incident response playbook
- Identity governance charter (Correct answer)
Correct answer: Identity governance charter
An identity governance charter establishes the mandate, scope, roles, and responsibilities for the IAM program, providing governance authority and accountability.
Question 74: Which NIST RBAC model level adds role hierarchies to the flat RBAC model?
- Symmetric RBAC
- Hierarchical RBAC (Correct answer)
- Constrained RBAC
- Core RBAC
Correct answer: Hierarchical RBAC
Hierarchical RBAC (NIST Level 2) adds senior/junior role relationships where senior roles inherit all permissions of junior roles, enabling permission reuse.
Question 75: Which privileged access control method limits what commands a sudo user can run by defining rules in a configuration file?
- Sudoers file (Correct answer)
- Access control list
- RBAC policy
- Group Policy Object
Correct answer: Sudoers file
The /etc/sudoers file defines granular rules specifying which users can run which commands with elevated privileges on Unix/Linux systems.
Question 76: What does the 'tombstoneLifetime' attribute in Active Directory control?
- The maximum age of Kerberos tickets
- How long a user account remains disabled before deletion
- How long deleted objects are retained before being permanently purged (Correct answer)
- The time limit for password resets
Correct answer: How long deleted objects are retained before being permanently purged
Tombstone lifetime defines how long deleted objects remain in the directory (default 180 days) so replication can propagate deletions before the object is fully purged.
Question 77: An organization classifies its CIAM data as 'Confidential.' What does this classification PRIMARILY dictate?
- The handling, storage, transmission, and disposal controls required for that data (Correct answer)
- The frequency of password resets
- The number of users allowed to access the system
- The color of the data labels on reports
Correct answer: The handling, storage, transmission, and disposal controls required for that data
Data classification determines the security controls and handling procedures that must be applied throughout the data lifecycle.
Question 78: What does a formal access rights review typically assess?
- Software license compliance across the organization
- Whether current user permissions align with job responsibilities and the least privilege principle (Correct answer)
- Password complexity and strength across all accounts
- Network performance and bandwidth utilization
Correct answer: Whether current user permissions align with job responsibilities and the least privilege principle
Access rights reviews compare users' current permissions against their actual job role requirements, identifying excessive, unused, or otherwise inappropriate access rights.
Question 79: What governance mechanism ensures that no single individual can both request AND approve their own access grant?
- Privileged access management
- Separation of duties in the approval workflow (Correct answer)
- Attribute-based access control
- Role-based access control
Correct answer: Separation of duties in the approval workflow
Separation of duties in approval workflows requires a different person to approve access than the one who requested it, preventing self-authorization fraud.
Question 80: Which replication topology model does Active Directory Sites and Services use by default to connect domain controllers?
- Full mesh
- KCC-generated spanning tree (Correct answer)
- Ring
- Hub and spoke
Correct answer: KCC-generated spanning tree
The Knowledge Consistency Checker (KCC) automatically generates a bidirectional ring/spanning-tree replication topology between domain controllers within and between sites.
Question 81: Which authentication security control directly reduces the risk of credential theft by ensuring passwords are never stored in plaintext?
- Session token expiration
- Password hashing with salt using bcrypt or Argon2 (Correct answer)
- Single sign-on federation
- Multi-factor authentication
Correct answer: Password hashing with salt using bcrypt or Argon2
Salted hashing with algorithms like bcrypt or Argon2 ensures that even if the database is breached, plaintext passwords cannot be recovered.
Question 82: Which metric measures the average time it takes an organization to detect a security breach within its CIAM environment?
- Recovery Time Objective (RTO)
- Mean Time to Detect (MTTD) (Correct answer)
- Mean Time to Repair (MTTR)
- Annual Loss Expectancy (ALE)
Correct answer: Mean Time to Detect (MTTD)
MTTD (Mean Time to Detect) measures the average elapsed time between a breach occurring and the organization identifying it.
Question 83: Which of the following is a key feature of an LDAP (Lightweight Directory Access Protocol) server in IAM?
- It encrypts communications between users and servers
- It tracks user activity on web applications
- It authenticates users by verifying biometric data
- It stores and retrieves identity-related information (Correct answer)
Correct answer: It stores and retrieves identity-related information
An LDAP (Lightweight Directory Access Protocol) server is a type of directory service widely used in IAM to store and retrieve identity-related information. It provides a centralized, hierarchical database for managing user accounts, groups, and other network resources, facilitating authentication and authorization.
Question 84: What is phishing?
- A network scanning tool
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
- A backup system
- A type of firewall
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 85: In a directory service context, what is 'federation' with an external IdP primarily used for?
- Replicating schema changes across forests
- Synchronizing directory objects between two domains
- Providing offline access to directory resources
- Allowing users from an external organization to authenticate using their own identity provider (Correct answer)
Correct answer: Allowing users from an external organization to authenticate using their own identity provider
Directory federation enables cross-organizational single sign-on by establishing trust so that an external IdP can assert authenticated user identities to local services.
Question 86: What is the primary purpose of 'identity proofing' in the context of Identity and Access Management?
- Auditing user activity after authentication
- Granting access permissions to verified users
- Encrypting identity credentials for secure storage
- Establishing confidence that a claimed identity corresponds to a real individual (Correct answer)
Correct answer: Establishing confidence that a claimed identity corresponds to a real individual
Identity proofing is the process of establishing confidence that a subject claiming an identity is actually who they claim to be, based on evidence and validation.
Question 87: Under CMMC Level 2, which practice domain requires organizations to control access to CUI based on least privilege?
- Access Control (AC) (Correct answer)
- Configuration Management (CM)
- Incident Response (IR)
- Audit and Accountability (AU)
Correct answer: Access Control (AC)
CMMC Level 2 Access Control (AC) practices require limiting system access to authorized users and implementing least privilege for CUI protection.
Question 88: When configuring RADIUS for network access authentication, what does the RADIUS server return when authentication succeeds?
- A JWT token
- A SAML assertion
- A Kerberos ticket
- An Access-Accept message with optional attributes (Correct answer)
Correct answer: An Access-Accept message with optional attributes
On successful authentication, a RADIUS server responds with an Access-Accept packet, optionally including vendor-specific attributes that grant network access or define access policy.
Question 89: Under FedRAMP, cloud service providers must implement identity controls based on which underlying framework?
- CIS Controls
- PCI DSS
- NIST SP 800-53 (Correct answer)
- ISO 27001
Correct answer: NIST SP 800-53
FedRAMP uses NIST SP 800-53 security controls as its foundation, including the AC (Access Control) and IA (Identification and Authentication) control families.
Question 90: Which component of a PAM architecture acts as a proxy to enforce session control and policy without exposing target system credentials to end users?
- Identity broker
- Privileged access gateway (Correct answer)
- Token service
- Directory server
Correct answer: Privileged access gateway
A privileged access gateway sits between the admin and the target system, injecting credentials and enforcing policy transparently.
Question 91: What is 'Privileged Session Management' (PSM)?
- A system for managing user authentication session tokens
- A capability that records, monitors, and controls sessions conducted by privileged users in real time (Correct answer)
- A browser session management tool for IT help desk staff
- A tool for managing end-user session timeouts
Correct answer: A capability that records, monitors, and controls sessions conducted by privileged users in real time
Privileged Session Management records all keystrokes and actions during privileged user sessions, enabling real-time monitoring, intervention, and forensic replay after incidents.
Question 92: In a zero-trust architecture, what does 'never trust, always verify' mean for authorization?
- Use blockchain-based verification for all authorization decisions
- Disable all existing trust relationships and require new credentials for every session
- Continuously validate identity, device health, and context before granting access regardless of network location (Correct answer)
- Require multi-factor authentication only for external network access
Correct answer: Continuously validate identity, device health, and context before granting access regardless of network location
Zero-trust mandates continuous verification of every access request using identity, device posture, and contextual signals, regardless of whether the request originates inside or outside the corporate network.
Question 93: A governance board wants to reduce identity-related risk without increasing operational burden. Which IAM initiative best balances both goals?
- Requiring all users to request access through a help desk ticket
- Expanding manual quarterly reviews to all user populations
- Removing all standing privileged access and requiring re-approval daily
- Implementing risk-based access certification that focuses reviews on high-risk accounts (Correct answer)
Correct answer: Implementing risk-based access certification that focuses reviews on high-risk accounts
Risk-based certification focuses review effort on the highest-risk accounts and entitlements, reducing compliance burden while improving overall risk posture.
Question 94: Which authentication protocol uses security assertions in XML format to exchange authentication and authorization data between an identity provider and a service provider?
- Kerberos
- OAuth 2.0
- SAML 2.0 (Correct answer)
- OpenID Connect
Correct answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) uses XML-based assertions to convey authentication and authorization information between identity providers and service providers.
Question 95: What is the PRIMARY purpose of a Risk Register in an IAM security program?
- To track user access permissions
- To define authentication policies for each application
- To document, prioritize, and monitor identified risks (Correct answer)
- To store audit logs for compliance purposes
Correct answer: To document, prioritize, and monitor identified risks
A Risk Register is a central repository for recording, assessing, prioritizing, and tracking risks and their treatment plans.
Question 96: What is 'IdP-initiated SSO'?
- SSO where the user starts at the service provider
- SSO that requires multi-factor authentication
- SSO that uses only LDAP directory lookups
- SSO where the authentication process begins at the identity provider (Correct answer)
Correct answer: SSO where the authentication process begins at the identity provider
In IdP-initiated SSO, the user first navigates to the Identity Provider, which authenticates them and then redirects to the target service with an assertion.
Question 97: Under the Zero Trust Architecture framework, which principle states that no user or device should be inherently trusted regardless of network location?
- Microsegmentation
- Never trust, always verify (Correct answer)
- Least privilege access
- Assume breach
Correct answer: Never trust, always verify
The 'never trust, always verify' principle is the foundational tenet of Zero Trust, requiring continuous authentication and authorization.
Question 98: What does 'identity validation' mean in the NIST SP 800-63A proofing process?
- Confirming the applicant's claimed identity matches an authoritative source (Correct answer)
- Determining that the identity attributes resolve to a unique person
- Verifying that an authenticator meets strength requirements
- Checking that a credential has not been revoked
Correct answer: Confirming the applicant's claimed identity matches an authoritative source
Identity validation confirms that the evidence provided is genuine (not forged) and that the identity information on the evidence is accurate by checking it against authoritative sources such as government databases.
Question 99: What is 'access creep' and why is it a concern in identity lifecycle management?
- Over-provisioning of birthright access during onboarding
- Accumulation of unnecessary privileges over time as roles change (Correct answer)
- Gradual reduction of access rights due to automation errors
- Unauthorized access obtained through phishing attacks
Correct answer: Accumulation of unnecessary privileges over time as roles change
Access creep occurs when users accumulate permissions from previous roles that are never revoked, violating least privilege and increasing breach risk.
Question 100: A healthcare system grants doctors read access to all patient records but write access only to their own patients' records. This scenario best illustrates which model?
- Chinese Wall Model
- ABAC (Correct answer)
- RBAC with object-level constraints
- Pure MAC
Correct answer: ABAC
ABAC can combine role attributes (doctor) with relationship attributes (my patient) and action attributes (read vs. write) to enforce this nuanced policy.
Question 101: When a CIAM system uses LDAP as a user store, which best practice ensures high availability for authentication requests?
- Deploy multiple LDAP replicas and configure the CIAM platform with failover or load-balanced connections (Correct answer)
- Use read-write connections to only one server to avoid replication conflicts
- Disable LDAP referrals so all requests are handled by the primary server
- Configure a single master LDAP server with daily backups
Correct answer: Deploy multiple LDAP replicas and configure the CIAM platform with failover or load-balanced connections
Multiple read replicas behind a load balancer or using a failover list ensures authentication continues even if one LDAP server becomes unavailable.
Question 102: What is encryption?
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Compressing files
- Backing up data
- Deleting data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
CIAM – Certified Identity and Access Manager
The CIAM certification is offered by the Identity Management Institute and validates expertise in identity governance, access management, authentication, risk management, and regulatory compliance. The exam consists of 100 multiple-choice questions to be completed in 90 minutes with a 70% passing score.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds