Security and Risk Management Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Risk Management flashcards as text
A CIAM platform uses JSON Web Tokens (JWTs) for session management. Which vulnerability arises when JWT signature verification is bypassed by setting the algorithm to 'none'?
Answer: Algorithm confusion attack
The 'alg:none' algorithm confusion attack allows attackers to forge tokens by stripping signature validation entirely.
Which security concept defines the maximum acceptable downtime for a CIAM authentication service before business operations are critically impacted?
Answer: Recovery Time Objective (RTO)
RTO defines the maximum tolerable length of time a system can be offline before the impact becomes unacceptable to the business.
What is the PRIMARY risk of allowing users to self-register without any verification in a CIAM system?
Answer: Account enumeration and fake account creation enabling fraud
Unverified self-registration enables fraudsters to create fake accounts for fraud, spam, or credential-stuffing cover.
Which principle requires that critical IAM tasks, such as provisioning and approving access, be divided between two or more individuals?
Answer: Separation of duties
Separation of duties prevents a single person from having end-to-end control over a critical process, reducing fraud and error risk.
An organization classifies its CIAM data as 'Confidential.' What does this classification PRIMARILY dictate?
Answer: The handling, storage, transmission, and disposal controls required for that data
Data classification determines the security controls and handling procedures that must be applied throughout the data lifecycle.
Which type of social engineering attack specifically targets high-ranking executives to trick them into authorizing large financial transactions or disclosing IAM credentials?
Answer: Whaling
Whaling is a spear-phishing variant that targets executives (C-suite) due to their elevated authority and access.
What is 'residual risk' in an IAM security program?
Answer: The remaining risk after security controls have been applied
Residual risk is the level of risk that persists after all mitigation controls have been implemented and accepted.