Identity Governance Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity Governance flashcards as text
Which process ensures that users only retain access rights that are still required for their current job function?
Answer: Access certification
Access certification (also called access review or recertification) periodically validates that user entitlements remain appropriate for their current role.
In identity governance, what does 'toxic combinations' refer to?
Answer: Conflicting permissions that violate SoD policy
Toxic combinations are pairs or groups of entitlements that, when held by the same user, create a Segregation of Duties (SoD) violation and increase fraud risk.
A governance policy requires that no single employee can create vendors AND approve payments. This is an example of:
Answer: Separation of duties
Separation of duties (SoD) prevents a single individual from controlling a complete high-risk process, reducing fraud and error risk.
What is the primary purpose of an identity governance 'fulfillment' workflow?
Answer: Automatically provisioning approved access requests
Fulfillment workflows execute the provisioning actions (granting or revoking access) after an access request has been approved.
Which metric best measures the effectiveness of an access review campaign?
Answer: Percentage of certifications completed on time
Certification completion rate measures how thoroughly reviewers fulfilled their obligation to validate user access, directly indicating review effectiveness.
What is 'role creep' in the context of identity governance?
Answer: The gradual accumulation of access rights beyond what a user needs
Role creep occurs when users accumulate privileges over time through job changes or project assignments without removal of previously granted rights.
In an IGA system, what does a 'policy violation' typically trigger?
Answer: A remediation workflow or alert for review
IGA systems surface policy violations (such as SoD conflicts) and trigger remediation workflows that route the issue to an approver or compliance team.