Identity Governance Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity Governance flashcards as text
What is 'birthright access' in an identity governance context?
Answer: Standard access automatically provisioned to all users based on their employment status
Birthright access refers to baseline entitlements (such as email and intranet access) that every new employee receives automatically upon joining.
During a leaver workflow, which action is most critical from an identity governance perspective?
Answer: Timely revocation of all entitlements across connected systems
Prompt deprovisioning across all systems prevents terminated employees from retaining unauthorized access, a key governance and security requirement.
What is the difference between 'coarse-grained' and 'fine-grained' access control in IGA?
Answer: Coarse-grained controls application-level access; fine-grained controls access to specific data or transactions within an application
Coarse-grained access determines whether a user can access an application, while fine-grained access controls specific actions or data within that application.
An organization assigns a single reviewer responsible for certifying 2,000 accounts. What governance risk does this create?
Answer: Rubber-stamping or reviewer fatigue
Assigning too many certifications to one reviewer leads to rubber-stamping, where reviewers approve access without meaningful review, undermining governance effectiveness.
Which IGA feature allows delegation of access approval authority to a substitute during a reviewer's absence?
Answer: Delegate/surrogate assignment
Delegate or surrogate assignment lets a reviewer temporarily transfer their certification or approval responsibilities to another authorized individual.
What is the governance purpose of tracking 'entitlement owner' in an IGA system?
Answer: To establish accountability for approving and reviewing access to that entitlement
Entitlement owners are responsible for approving requests and certifying who should have access, creating a clear accountability chain for each permission.
Which concept describes automatically removing access that has not been used within a defined period?
Answer: Access expiry or time-based deprovisioning
Time-based or usage-based deprovisioning automatically revokes entitlements that show no activity within a configured window, reducing unnecessary access sprawl.