Technology and Tools Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technology and Tools flashcards as text
An enterprise deploys a tool that analyzes user behavior baselines and flags anomalous access patterns. What category does this tool fall under?
Answer: User and Entity Behavior Analytics (UEBA)
UEBA tools use machine learning to establish behavioral baselines and detect anomalies that may indicate compromised accounts.
Which component of a CIAM platform is responsible for managing the user registration and self-service profile update experience?
Answer: Customer-facing identity portal / self-service UI
The customer-facing identity portal handles self-registration, profile management, and consent collection for end consumers.
What is the function of an OAuth 2.0 authorization server's 'token introspection' endpoint?
Answer: To allow resource servers to validate and inspect active tokens
Token introspection (RFC 7662) lets a resource server query the authorization server to determine whether a token is active and retrieve its metadata.
In a federated identity model, which entity makes the authentication decision and asserts the user's identity to a relying party?
Answer: The Identity Provider (IdP)
The Identity Provider authenticates the user and issues assertions (e.g., SAML or OIDC tokens) to the relying party.
Which PKI component is used to declare that a previously issued certificate should no longer be trusted before its expiration?
Answer: Certificate Revocation List (CRL) or OCSP
A CRL or OCSP provides revocation status so relying parties know whether a certificate has been invalidated before its natural expiry.
Which deployment model for an IAM solution places the IAM infrastructure entirely within the organization's own data center?
Answer: On-premises
An on-premises IAM deployment runs all IAM components within the organization's own infrastructure, giving full control but requiring internal maintenance.
What technology allows passwordless authentication by using a private key stored on a device and a public key registered with a service?
Answer: FIDO2 / WebAuthn
FIDO2/WebAuthn uses asymmetric cryptography where the private key never leaves the device, enabling phishing-resistant passwordless login.