Authentication Methods Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Authentication Methods flashcards as text
Which authentication protocol uses security assertions in XML format to exchange authentication and authorization data between an identity provider and a service provider?
Answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) uses XML-based assertions to convey authentication and authorization information between identity providers and service providers.
What is the primary purpose of a TOTP (Time-based One-Time Password) in multi-factor authentication?
Answer: To generate a short-lived code synchronized with a time clock
TOTP generates a numeric code derived from a shared secret and the current time, typically valid for 30 seconds, adding a time-sensitive second factor.
In certificate-based authentication, what cryptographic artifact does the client present to prove identity?
Answer: A digital certificate containing the client's public key
Certificate-based authentication requires the client to present a digital certificate (e.g., X.509) containing its public key, signed by a trusted Certificate Authority.
An organization wants to allow users to log in with their corporate credentials on a third-party SaaS application without sharing passwords. Which federation approach is most appropriate?
Answer: SAML-based SSO
SAML-based SSO enables federated identity so users authenticate at the corporate IdP and the SaaS SP accepts the assertion, never receiving the user's password.
What differentiates step-up authentication from standard MFA?
Answer: Step-up authentication triggers additional factors when elevated risk or privilege is detected
Step-up authentication dynamically requires additional verification factors when a user attempts a higher-risk action or accesses sensitive resources during an existing session.
Which of the following best describes a 'possession factor' in multi-factor authentication?
Answer: Something the user has, like a hardware token
A possession factor ('something you have') includes physical or virtual items the user owns, such as a hardware token, smart card, or mobile authenticator app.
When implementing passwordless authentication using FIDO2/WebAuthn, what is stored on the server side?
Answer: The user's public key and credential ID
In FIDO2/WebAuthn, the server (relying party) stores only the user's public key and credential ID; the private key never leaves the user's authenticator device.