โ† All CIAM Flashcard Decks

Authentication Methods Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Authentication Methods flashcards as text
  1. An enterprise deploys an adaptive authentication policy that increases friction when a user logs in from a new country. This approach is best described as:

    Answer: Risk-based or contextual authentication

    Risk-based (contextual) authentication dynamically adjusts the authentication challenge based on contextual risk signals such as location, device, and behavior anomalies.

  2. Which standard defines the protocol for verifying biometric data on a device without sending biometric templates to a remote server?

    Answer: FIDO2 / WebAuthn

    FIDO2/WebAuthn is designed so biometric data (fingerprint, face) is verified locally on the authenticator device and only a cryptographic proof is sent to the server.

  3. What is the primary security risk of allowing authentication via email magic links?

    Answer: The email channel itself may be compromised, allowing interception of the link

    If an attacker has access to the user's email account, they can intercept the magic link and authenticate as that user, making email account security critical to this method.

  4. In a federated identity scenario, which party is responsible for authenticating the user and issuing assertions?

    Answer: Identity Provider (IdP)

    The Identity Provider (IdP) authenticates the user and issues assertions (e.g., SAML assertions or OIDC tokens) that service providers trust to grant access.

  5. Which of the following is a security advantage of using OAuth 2.0 Authorization Code flow with PKCE over the Implicit flow for single-page applications?

    Answer: PKCE prevents authorization code interception attacks without requiring a client secret

    PKCE (Proof Key for Code Exchange) uses a code challenge/verifier pair to prevent authorization code interception attacks, making it safe for public clients that cannot store secrets.

  6. A company wants to implement continuous authentication that monitors user behavior throughout a session, not just at login. Which technology approach supports this?

    Answer: Behavioral biometrics and anomaly detection

    Behavioral biometrics (typing patterns, mouse movements) and ML-based anomaly detection can continuously verify user identity throughout a session beyond the initial login event.

  7. When configuring RADIUS for network access authentication, what does the RADIUS server return when authentication succeeds?

    Answer: An Access-Accept message with optional attributes

    On successful authentication, a RADIUS server responds with an Access-Accept packet, optionally including vendor-specific attributes that grant network access or define access policy.