Authorization Frameworks Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Authorization Frameworks flashcards as text
Which OAuth 2.0 response type is used in the Authorization Code flow to initiate the token exchange?
Answer: code
The 'code' response type instructs the authorization server to return an authorization code in the redirect, which the client then exchanges for tokens at the token endpoint.
In RBAC, what is 'role explosion' and why is it a concern?
Answer: When the number of roles grows unmanageable due to over-specialization of permissions
Role explosion occurs when organizations create too many highly specific roles to handle edge cases, making the RBAC system complex and difficult to administer.
What is the purpose of the 'nonce' parameter in OpenID Connect authorization requests?
Answer: To bind the ID token to the client session and prevent token replay
The nonce is a random value included in the authorization request and embedded in the resulting ID token, allowing the client to verify the token was issued for its specific session.
Which standard defines the structure and claims of JSON Web Tokens (JWT)?
Answer: RFC 7519
RFC 7519 defines the JSON Web Token (JWT) standard, including its structure (header, payload, signature) and a set of reserved claim names.
In a zero-trust architecture, what does 'never trust, always verify' mean for authorization?
Answer: Continuously validate identity, device health, and context before granting access regardless of network location
Zero-trust mandates continuous verification of every access request using identity, device posture, and contextual signals, regardless of whether the request originates inside or outside the corporate network.
Which OAuth 2.0 mechanism allows a client to obtain a new access token without user interaction after the original token expires?
Answer: Using the refresh token at the token endpoint
A refresh token is a long-lived credential issued alongside the access token that allows the client to obtain new access tokens from the token endpoint without requiring user re-authentication.
What is 'delegated authorization' in the context of OAuth 2.0?
Answer: A user authorizing a third-party application to access resources on their behalf without sharing credentials
OAuth 2.0 enables delegated authorization, where a resource owner grants a client limited access to their resources at a resource server without sharing their credentials with the client.