Identity Governance Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity Governance flashcards as text
Which IGA capability allows organizations to model 'what-if' scenarios before granting access?
Answer: Role simulation
Role simulation lets administrators preview the SoD impact and effective permissions of adding or removing a role before applying the change.
How does identity governance support compliance with regulations like SOX and HIPAA?
Answer: By enforcing access controls and maintaining auditable entitlement records
IGA provides the audit trails, certification records, and policy enforcement needed to demonstrate that access to regulated data is appropriately controlled.
A user transfers from Finance to Marketing. Which IGA process should automatically adjust their access?
Answer: Mover workflow
The Mover workflow handles internal transfers, revoking role-based access from the old position and provisioning access appropriate for the new one.
What distinguishes a 'business role' from a 'technical role' in IGA?
Answer: Business roles map job functions to entitlement sets; technical roles map directly to system permissions
Business roles are logical groupings aligned to job functions (e.g., 'Financial Analyst'), while technical roles represent specific system-level permission sets.
Which approach to role definition starts by analyzing existing user-to-entitlement assignments to discover implicit roles?
Answer: Bottom-up role mining
Bottom-up role mining uses data analytics on existing entitlement assignments to identify common access patterns and suggest role definitions.
In identity governance, what is the 'entitlement catalog'?
Answer: A centralized, searchable inventory of all available permissions and resources
The entitlement catalog provides a structured, business-friendly view of all permissions available for request, enabling self-service access management.
Which governance control prevents a user from approving their own access request?
Answer: Self-approval restriction
Self-approval restrictions are a governance control that routes access requests to a different approver when the requester and approver would otherwise be the same person.