Identity Lifecycle Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity Lifecycle flashcards as text
Which lifecycle phase is responsible for ensuring that a user's identity attributes remain accurate and current throughout their tenure?
Answer: Identity maintenance
Identity maintenance covers ongoing updates to attributes such as name, title, department, and contact information to keep identity data accurate over time.
A contractor's account should ideally have which feature to enforce a natural offboarding without manual intervention?
Answer: Automatic expiration date aligned with contract end date
Setting an account expiration date tied to the contract end date ensures automatic disablement without relying on a manual process that could be missed.
What is the function of a 'leaver' workflow in the JML (Joiner-Mover-Leaver) framework?
Answer: Revoking all entitlements and disabling accounts for departing users
The leaver workflow orchestrates the revocation of all access, disablement of accounts, and archival or deletion of identity data when a user departs.
Which control helps prevent 'ghost accounts'—active accounts belonging to users who have left the organization?
Answer: Periodic access reconciliation against the HR system
Reconciling the IAM directory against the authoritative HR system on a scheduled basis detects accounts that should have been deprovisioned but weren't.
In identity lifecycle management, what is a 'role explosion' risk?
Answer: An unmanageable proliferation of fine-grained roles that increases complexity
Role explosion occurs when organizations create too many granular roles, making role management, assignment, and certification unmanageable.
When a user is rehired after a gap in employment, what is the recommended practice for their identity account?
Answer: Use the archived account but require a full access re-certification before activation
Restoring an archived account with a re-certification step ensures the rehired employee gets appropriate access for their new role without inheriting stale entitlements.
What governance mechanism ensures that no single individual can both request AND approve their own access grant?
Answer: Separation of duties in the approval workflow
Separation of duties in approval workflows requires a different person to approve access than the one who requested it, preventing self-authorization fraud.