← All CIAM Flashcard Decks

Authentication Methods Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Authentication Methods flashcards as text
  1. Which risk-based authentication signal is most commonly used to detect an anomalous login attempt that warrants step-up verification?

    Answer: IP geolocation and device fingerprint changes

    Risk-based authentication engines primarily evaluate contextual signals like IP geolocation changes, unfamiliar devices, and unusual access patterns to flag suspicious logins.

  2. In the context of IAM, what is the key security benefit of using hardware security keys (e.g., YubiKey) over SMS-based OTP?

    Answer: Hardware keys are immune to SIM-swapping and phishing attacks

    Hardware security keys are phishing-resistant because they use origin-bound cryptographic challenges, and they cannot be compromised by SIM-swapping attacks that target SMS OTP.

  3. Which OAuth 2.0 grant type is recommended for machine-to-machine (M2M) authentication where no user is involved?

    Answer: Client Credentials

    The Client Credentials grant type is designed for server-to-server authentication where the client acts on its own behalf using its own client ID and secret, with no user context.

  4. A user presents a smartcard to authenticate to a workstation. The workstation validates the certificate chain against a CRL. What does CRL stand for?

    Answer: Certificate Revocation List

    A Certificate Revocation List (CRL) is a published list of digital certificates that have been revoked by the issuing CA before their expiration date.

  5. What is the purpose of the 'nonce' parameter in OpenID Connect authentication requests?

    Answer: To prevent replay attacks by binding the token to the specific request

    The nonce is a random value included in the authentication request and embedded in the ID token, allowing the client to verify the token was issued in response to that specific request.

  6. Which authentication method is considered most vulnerable to credential stuffing attacks?

    Answer: Single-factor username/password authentication

    Single-factor username/password authentication is highly susceptible to credential stuffing because attackers can test breached credential lists against the login endpoint at scale.

  7. In Kerberos authentication, what is the role of the Key Distribution Center (KDC)?

    Answer: To issue tickets that allow users to authenticate to services without re-entering credentials

    The KDC issues Ticket Granting Tickets (TGTs) and service tickets, enabling users to authenticate to network services without transmitting passwords across the network.