โ† All CIAM Flashcard Decks

Authorization Frameworks Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Authorization Frameworks flashcards as text
  1. Which JWT claim specifies the intended audience for the token and should be validated by the recipient?

    Answer: aud (audience)

    The 'aud' claim identifies the recipients for whom the JWT is intended; recipients must verify that they are included in the audience to prevent token misuse.

  2. In OAuth 2.0 Device Authorization Grant (RFC 8628), what is the 'user_code' used for?

    Answer: It is entered by the user at a secondary device to approve the authorization request

    The user_code is a short, human-readable code displayed on the device that the user enters on a secondary device (e.g., phone or computer) to approve the authorization request.

  3. What is 'scope downscoping' in OAuth 2.0 token exchange (RFC 8693)?

    Answer: Issuing a new token with a reduced set of scopes from the original token

    Scope downscoping in token exchange means the newly issued token has fewer or more restricted scopes than the original token, applying least-privilege for specific delegated operations.

  4. In ABAC, what is a 'policy information point' (PIP) responsible for?

    Answer: Retrieving attribute values needed to evaluate a policy

    The Policy Information Point (PIP) retrieves attribute values (user, resource, or environmental) from external sources such as LDAP, databases, or APIs to support policy evaluation.

  5. Which of the following is a key advantage of externalized authorization over embedding authorization logic in application code?

    Answer: Policies can be updated centrally without redeploying applications

    Externalized authorization decouples policy management from application code, allowing security teams to update, audit, and enforce policies centrally without requiring application changes or redeployments.

  6. What does the 'iss' (issuer) claim in a JWT identify, and why is validating it important?

    Answer: The authorization server that issued the token; validating it ensures the token comes from a trusted source

    The 'iss' claim identifies the authorization server that issued the JWT; recipients must validate it to ensure the token was not issued by an untrusted or malicious authorization server.

  7. Which authorization pattern is most appropriate when a microservice needs to make access decisions based on data it does not own, without coupling tightly to the owning service?

    Answer: Use a centralized Policy Decision Point (PDP) with an externalized policy engine

    A centralized PDP with an externalized policy engine (e.g., OPA, Cedar) decouples authorization logic from microservice code, enabling consistent policy enforcement without tight service coupling.

Authorization Frameworks Flashcards โ€” CIAM Study Cards with Answers