โ† All CIAM Flashcard Decks

Foundational Frameworks Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Foundational Frameworks flashcards as text
  1. Which IAM concept describes a situation where an employee accumulates access rights over time beyond what their current role requires?

    Answer: Privilege creep

    Privilege creep (or access creep) occurs when users retain permissions from previous roles that are no longer necessary for their current job function.

  2. According to the SABSA (Sherwood Applied Business Security Architecture) framework, which layer directly addresses operational security management?

    Answer: Operational layer

    SABSA's Operational layer addresses the people, processes, and procedures that run and manage the security solution in day-to-day operations.

  3. In XACML (eXtensible Access Control Markup Language), which component evaluates a policy request and returns an authorization decision?

    Answer: Policy Decision Point (PDP)

    The PDP evaluates access requests against applicable policies and returns permit, deny, or indeterminate decisions.

  4. Which concept in IAM governance defines the separation of identity lifecycle management responsibilities so no single administrator can create, enable, and assign privileges to an account alone?

    Answer: Segregation of duties

    Segregation of duties (SoD) splits critical IAM tasks among multiple individuals to prevent fraud and reduce insider threat risk.

  5. A company implements a system where access decisions are based on employee department, job title, and work location attributes. This is an example of which access control model?

    Answer: Attribute-Based Access Control (ABAC)

    ABAC evaluates multiple attributes of the subject, resource, and environment to make fine-grained access control decisions.

  6. Which ISO standard specifically addresses information security management systems (ISMS) and is directly relevant to IAM program governance?

    Answer: ISO/IEC 27001

    ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS, which includes IAM controls.

  7. In Privileged Access Management (PAM), what is a 'just-in-time' (JIT) access approach designed to prevent?

    Answer: Standing persistent privileged access that increases attack surface

    JIT access grants elevated privileges only when needed and for a limited time, eliminating standing privileged accounts that attackers can exploit.