← All CIAM Flashcard Decks

Technology and Tools Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technology and Tools flashcards as text
  1. Which IAM technology is primarily used to manage access to network resources such as VPNs and Wi-Fi using a centralized authentication protocol?

    Answer: RADIUS

    RADIUS (Remote Authentication Dial-In User Service) is widely used to authenticate network access requests for VPNs, Wi-Fi, and network equipment.

  2. What is 'identity proofing' in a CIAM context, and which tool category supports it?

    Answer: Verifying a user's claimed identity using authoritative sources, supported by ID verification / KYC platforms

    Identity proofing verifies that a person is who they claim to be, typically using document scanning and biometrics via KYC (Know Your Customer) platforms.

  3. Which protocol extension allows an OAuth 2.0 server to provide user identity information to a client application in a signed JWT format?

    Answer: ID Token via OpenID Connect

    OpenID Connect extends OAuth 2.0 by adding an ID Token — a signed JWT containing user identity claims — returned alongside the access token.

  4. A CIAM platform must handle millions of concurrent user sessions for a consumer app. Which characteristic is most critical to evaluate?

    Answer: Horizontal scalability and multi-region availability

    Consumer-scale CIAM platforms must scale horizontally and operate across multiple regions to handle high concurrency and ensure availability.

  5. Which IAM capability detects when a user is granted access rights that, in combination, create a Segregation of Duties (SoD) conflict?

    Answer: SoD conflict detection in IGA platforms

    IGA platforms include SoD conflict detection engines that flag or prevent granting access combinations that violate separation-of-duties policies.

  6. What is the purpose of 'session binding' in a web SSO deployment?

    Answer: Linking the SSO session to a specific browser instance or device to prevent session hijacking

    Session binding ties an authenticated session to identifiers like a device fingerprint or cookie to reduce the risk of stolen session tokens being used elsewhere.

  7. In a hybrid IAM environment, what is the typical role of an 'identity bridge' or 'federation gateway'?

    Answer: To translate between different identity protocols (e.g., Kerberos on-prem to SAML/OIDC in cloud)

    An identity bridge or federation gateway converts authentication assertions between protocols, allowing on-premises Kerberos sessions to be federated to cloud services via SAML or OIDC.