Privileged Access Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privileged Access flashcards as text
Which best practice addresses the risk of an administrator using a single account for both privileged and non-privileged tasks?
Answer: Requiring separate admin and standard user accounts
Maintaining separate accounts for privileged and day-to-day activities limits the exposure of admin credentials during routine browsing or email.
What is the main risk of using shared privileged accounts (e.g., a single 'root' account used by multiple administrators)?
Answer: Inability to attribute actions to a specific individual
Shared accounts break accountability because audit logs cannot determine which individual performed a privileged action.
A cloud administrator is granted temporary elevated access via an automated workflow that expires after 4 hours. This is an example of:
Answer: Just-in-time (JIT) privileged access
Just-in-time privileged access grants elevated permissions on-demand for a limited time window and revokes them automatically.
Which control helps detect a compromised privileged account by establishing a baseline of normal behavior and alerting on deviations?
Answer: User and Entity Behavior Analytics (UEBA)
UEBA uses machine learning to model normal privileged user behavior and flags anomalous activities that may indicate compromise.
In a PAM deployment, what is the purpose of 'application-to-application password management' (AAPM)?
Answer: To eliminate hard-coded credentials in scripts and applications by fetching secrets at runtime
AAPM removes hard-coded or embedded credentials from applications by having them retrieve secrets dynamically from a vault.
Which principle states that a privileged user should only be able to access systems relevant to their specific administrative function?
Answer: Need-to-know
Need-to-know restricts access to information or systems based on whether access is necessary for the user's defined job function.
An organization discovers that a terminated contractor's service account is still active and has domain admin rights. Which process failure does this represent?
Answer: Failure of offboarding/deprovisioning procedures
Proper offboarding must include immediate deprovisioning of all accounts, especially privileged ones, to prevent unauthorized access after termination.