Identity Lifecycle Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity Lifecycle flashcards as text
Which metric is most useful for measuring the effectiveness of an organization's offboarding process?
Answer: Mean time to deprovision access after a termination event
Mean time to deprovision (MTTD) directly measures how quickly access is revoked after departure, indicating offboarding process efficiency and risk exposure.
An employee moves from Finance to Engineering. Under least privilege, which action is most appropriate for their Finance system access?
Answer: Revoke Finance access immediately upon role change
Least privilege requires revoking access to systems no longer needed for the new role immediately upon the mover event, not retaining it as a convenience.
What is the primary purpose of maintaining an identity audit trail throughout the lifecycle?
Answer: To provide accountability and evidence for compliance investigations
An identity audit trail records all lifecycle events—creation, modification, access grants, and deletion—to support compliance, forensic investigations, and accountability.
Which approach best handles identity lifecycle management for a large organization with multiple HR systems across subsidiaries?
Answer: Use a meta-directory or identity broker to aggregate authoritative data from all HR sources
A meta-directory or identity broker aggregates identity data from multiple authoritative sources, providing a unified view for lifecycle management without requiring HR system consolidation.
What is 'role mining' used for in identity lifecycle management?
Answer: Analyzing existing access patterns to discover and define roles
Role mining analyzes users' actual access entitlements to identify patterns and derive role definitions, supporting the transition to role-based access control.
Which regulation most directly mandates timely access revocation as part of identity lifecycle controls for US healthcare organizations?
Answer: HIPAA Security Rule
The HIPAA Security Rule requires covered entities to implement procedures for terminating access of workforce members, making timely deprovisioning a compliance obligation.
In a cloud-centric identity architecture, which capability allows lifecycle changes in the identity provider to propagate automatically to downstream SaaS applications?
Answer: SCIM push provisioning
SCIM push provisioning sends real-time lifecycle events (create, update, delete) from the identity provider to SaaS applications, keeping identities synchronized automatically.