Mixed Deck — All CIAM Topics Flashcards
100 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CIAM Topics flashcards as text
What is the purpose of access certification campaigns?
Answer: Periodically verifying that users retain only appropriate access rights by having managers review and approve
Access certification campaigns periodically require managers or system owners to review and confirm that each user's access rights remain appropriate for their current role.
Which NIST 800-63B authenticator assurance level (AAL) requires the use of a phishing-resistant, hardware-bound authenticator?
Answer: AAL3
NIST AAL3 requires a hardware-based authenticator with verifier impersonation resistance (phishing-resistant), providing the highest level of authentication assurance.
What is the main purpose of Role-Based Access Control (RBAC) in an IAM framework?
Answer: To control the access of individual users based on their role within the organization
Role-Based Access Control (RBAC) is a method of restricting system access based on the roles of individual users within an organization. It ensures that users are granted only the necessary permissions to perform their job functions, simplifying access management and enhancing security.
Which standard defines a common schema for representing user and group objects across identity systems?
Answer: SCIM 2.0
SCIM 2.0 defines a standardized schema and REST API for user and group provisioning across cloud-based systems.
What is 'orphan account' detection in IAM?
Answer: Identifying active accounts that remain after the associated employee has left or changed roles
Orphan account detection identifies accounts that remain enabled after the associated user has been terminated or transferred, reducing the attack surface from stale credentials.
A CIAM platform uses JSON Web Tokens (JWTs) for session management. Which vulnerability arises when JWT signature verification is bypassed by setting the algorithm to 'none'?
Answer: Algorithm confusion attack
The 'alg:none' algorithm confusion attack allows attackers to forge tokens by stripping signature validation entirely.
Under the EU AI Act's risk-based framework, which category of AI system would an automated identity verification system used for high-stakes decisions most likely fall into?
Answer: High risk
AI systems used for biometric identification or access decisions in high-stakes contexts are classified as high-risk under the EU AI Act and subject to strict requirements.
A user presents a smartcard to authenticate to a workstation. The workstation validates the certificate chain against a CRL. What does CRL stand for?
Answer: Certificate Revocation List
A Certificate Revocation List (CRL) is a published list of digital certificates that have been revoked by the issuing CA before their expiration date.
A compliance auditor asks for evidence that privileged access is reviewed quarterly. Which IAM artifact best satisfies this request?
Answer: Completed access certification reports with timestamps
Completed access certification reports with timestamps demonstrate that privileged accounts were reviewed at the required frequency.
A Zero Trust Architecture primarily challenges which traditional access control assumption?
Answer: Resources inside the network perimeter are trusted by default
Zero Trust eliminates implicit trust for internal network traffic, requiring explicit verification of every access request regardless of network location.
Which study approach is most effective for Authorization Frameworks material?
Answer: Active recall with practice questions
Active recall through practice questions is the most effective study method, as it strengthens memory retrieval pathways.
What is the primary purpose of maintaining an identity audit trail throughout the lifecycle?
Answer: To provide accountability and evidence for compliance investigations
An identity audit trail records all lifecycle events—creation, modification, access grants, and deletion—to support compliance, forensic investigations, and accountability.
What is 'SP-initiated SSO'?
Answer: SSO where the user first accesses the Service Provider, which redirects to the IdP
In SP-initiated SSO, the user first attempts to access a resource at the Service Provider, which then redirects them to the Identity Provider for authentication.
What is encryption?
Answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
A CIAM risk assessment reveals that a specific threat has a high likelihood but a low impact. How should this risk TYPICALLY be prioritized?
Answer: Monitored and assigned a medium priority
High likelihood combined with low impact generally places a risk in the medium priority range, requiring monitoring but not emergency response.
What is the primary purpose of threat analysis in IAM?
Answer: To identify potential security risks that could compromise access to systems and data
The primary purpose of threat analysis in IAM is to proactively identify potential security risks and vulnerabilities that could compromise access to systems and data. By understanding these threats, organizations can develop strategies and controls to mitigate them before they can be exploited.
Which Azure AD feature allows administrators to control which users and groups can access a specific enterprise application?
Answer: User assignment required
Enabling 'User assignment required' on an enterprise application restricts access so only explicitly assigned users or groups can authenticate to that app.
Which type of social engineering attack specifically targets high-ranking executives to trick them into authorizing large financial transactions or disclosing IAM credentials?
Answer: Whaling
Whaling is a spear-phishing variant that targets executives (C-suite) due to their elevated authority and access.
How does identity governance support compliance with regulations like SOX and HIPAA?
Answer: By enforcing access controls and maintaining auditable entitlement records
IGA provides the audit trails, certification records, and policy enforcement needed to demonstrate that access to regulated data is appropriately controlled.
Which attribute in Active Directory stores the last time a user successfully authenticated, and why is it sometimes disabled in large environments?
Answer: lastLogon, because it is domain-controller-local and not replicated
lastLogon is updated on every authentication but is NOT replicated between domain controllers, so each DC holds only its own view; lastLogonTimestamp is replicated but intentionally delayed.