Identity Governance Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity Governance flashcards as text
What does 'peer group analysis' contribute to identity governance?
Answer: It detects outlier access that differs significantly from similar users' entitlements
Peer group analysis compares a user's entitlements to those of colleagues in the same role or department to surface anomalous access that may be excessive or inappropriate.
In identity governance, what is the risk of 'orphaned accounts'?
Answer: They provide a persistent attack surface since no owner monitors or manages them
Orphaned accounts belong to departed employees or decommissioned systems and remain active without oversight, making them prime targets for attackers.
Which governance mechanism ensures that high-risk access requests receive additional scrutiny before approval?
Answer: Risk-based or multi-level approval workflows
Risk-based approval workflows route sensitive or high-risk access requests through additional approvers (such as security or compliance teams) beyond the standard manager approval.
How does identity governance differ from identity administration?
Answer: Governance focuses on policy, risk, and compliance; administration focuses on provisioning and technical tasks
Identity governance encompasses the business controls, risk management, and compliance oversight of identities, while identity administration handles the technical provisioning and lifecycle operations.
What is 'access request justification' and why is it required in IGA?
Answer: A business reason provided with an access request to enable risk-informed approval decisions
Requiring a business justification helps approvers make informed decisions, creates an audit trail of why access was granted, and deters unnecessary requests.
Which IGA concept describes assigning access based on a user's verified attributes such as department, location, and clearance level?
Answer: Attribute-Based Access Control (ABAC)
ABAC grants access dynamically based on evaluated attributes of the user, resource, and environment, enabling fine-grained, contextual access decisions.
A company's IGA audit reveals that 40% of certifications were approved in under 10 seconds. What does this most likely indicate?
Answer: Reviewers are rubber-stamping approvals without due diligence
Extremely fast approval times across many certifications are a strong indicator of rubber-stamping, where reviewers click approve without meaningful review of the entitlements.