Directory Services Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Directory Services flashcards as text
In the context of CIAM, why is LDAP's hierarchical directory structure sometimes less suitable than a flat-schema database for consumer identity storage?
Answer: Consumer identity data is often highly varied and unstructured, fitting poorly into rigid schema-based hierarchies
Consumer identity attributes vary widely across users and change frequently, which conflicts with the strict, schema-enforced object class model of traditional LDAP directories.
What is 'directory virtualization' in an enterprise IAM architecture?
Answer: A layer that presents a unified LDAP or SCIM interface over multiple heterogeneous identity stores without moving data
Directory virtualization (e.g., RadiantOne, Oracle OUVD) aggregates multiple disparate identity stores into a single virtual namespace exposed via standard protocols.
Which attribute in Active Directory stores the last time a user successfully authenticated, and why is it sometimes disabled in large environments?
Answer: lastLogon, because it is domain-controller-local and not replicated
lastLogon is updated on every authentication but is NOT replicated between domain controllers, so each DC holds only its own view; lastLogonTimestamp is replicated but intentionally delayed.
What LDAP control (OID 1.2.840.113556.1.4.319) enables a client to page through large search result sets?
Answer: Simple Paged Results control
The Simple Paged Results control (RFC 2696) allows clients to retrieve large search results in manageable pages by passing a cookie back and forth with the server.
In Azure Active Directory, what does 'Seamless Single Sign-On' (Seamless SSO) accomplish for domain-joined devices?
Answer: It automatically signs users into Azure AD apps without requiring additional prompts when they are on the corporate network
Seamless SSO uses Kerberos tickets obtained from on-premises AD to silently authenticate domain-joined machines to Azure AD, eliminating re-prompts on the corporate network.
What is 'DSML' (Directory Services Markup Language) and why has it largely been superseded?
Answer: An XML-based protocol for representing LDAP operations over HTTP, superseded by SCIM's simpler JSON REST API
DSML wrapped LDAP operations in XML for HTTP transport, but SCIM 2.0's lightweight JSON REST model proved easier to implement and became the modern standard.
When a CIAM system uses LDAP as a user store, which best practice ensures high availability for authentication requests?
Answer: Deploy multiple LDAP replicas and configure the CIAM platform with failover or load-balanced connections
Multiple read replicas behind a load balancer or using a failover list ensures authentication continues even if one LDAP server becomes unavailable.