Identity Lifecycle Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity Lifecycle flashcards as text
Which standard protocol is commonly used for automated provisioning and deprovisioning of identities across cloud services?
Answer: SCIM 2.0
SCIM (System for Cross-domain Identity Management) is the industry-standard protocol designed specifically for automating user provisioning across cloud applications.
What is 'access creep' and why is it a concern in identity lifecycle management?
Answer: Accumulation of unnecessary privileges over time as roles change
Access creep occurs when users accumulate permissions from previous roles that are never revoked, violating least privilege and increasing breach risk.
An access certification campaign is best described as:
Answer: A periodic review where managers confirm or revoke user entitlements
Access certification (or access review) is a recurring process where account owners or managers attest that users' current access is still appropriate.
Which lifecycle event most commonly triggers a re-certification review of all existing user access?
Answer: A significant organizational restructuring or merger
Organizational restructuring or mergers can invalidate existing role structures, making a full access review necessary to ensure entitlements remain appropriate.
In a federated identity model, who manages the authoritative lifecycle data for an external partner's employees?
Answer: The partner organization's own identity provider
In federation, the partner's own identity provider is authoritative for their employees' lifecycle data, reducing administrative burden on the relying party.
What is the key difference between account disablement and account deletion in offboarding workflows?
Answer: Disablement preserves the account and data for audit; deletion removes them
Disabling an account blocks access while retaining the account and associated data for audit trails, litigation holds, and knowledge transfer; deletion is irreversible.
What does 'just-in-time (JIT) provisioning' mean in identity lifecycle management?
Answer: An account is created automatically at the moment of a user's first authentication
JIT provisioning creates user accounts on-demand during the first authentication event, reducing administrative overhead and the risk of stale pre-provisioned accounts.