โ† All CIAM Flashcard Decks

Technology and Tools Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Technology and Tools flashcards as text
  1. Which IAM tool feature automatically removes access rights when an employee changes roles or departments?

    Answer: Automated deprovisioning / role reconciliation

    Automated deprovisioning or role reconciliation ensures access rights are adjusted when HR systems report a role change.

  2. In an IAM context, what is a 'connector' or 'agent' in provisioning tools?

    Answer: A software component that translates IAM commands to a target system's native API

    A connector or provisioning agent adapts the IAM platform's generic provisioning requests to the specific APIs or protocols of the target application.

  3. Which standard is specifically designed to enable SSO for web browser-based applications using XML-based assertions?

    Answer: SAML 2.0

    SAML 2.0 uses XML-based assertions passed via browser redirects to enable SSO between an identity provider and service providers.

  4. What is the role of a 'Policy Enforcement Point' (PEP) in an IAM architecture?

    Answer: It intercepts requests and enforces authorization decisions received from a Policy Decision Point

    The PEP sits in the request path, intercepts access requests, and enforces the allow/deny decision made by the Policy Decision Point (PDP).

  5. An IAM team wants to correlate identity events with security alerts in real time. Which tool integration is most relevant?

    Answer: Integrating the IAM system with a SIEM platform

    Integrating IAM with a SIEM allows security teams to correlate identity events (logins, permission changes) with broader security telemetry.

  6. Which feature of modern IAM platforms allows policies to be expressed and evaluated in a standardized, human-readable policy language?

    Answer: XACML or OPA (Open Policy Agent)

    XACML and OPA are policy languages/engines that allow fine-grained, externalized authorization policies to be written and enforced consistently.

  7. In OAuth 2.0, which grant type is most appropriate for a server-to-server integration where no user is involved?

    Answer: Client Credentials

    The Client Credentials grant is used for machine-to-machine communication where the application authenticates with its own client ID and secret, without a user context.