← All CISSP Flashcard Decks

Identity and Access Management Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Identity and Access Management flashcards as text
  1. Which federation standard allows identity assertions to be passed between domains using XML-based tokens?

    Answer: SAML 2.0

    SAML 2.0 (Security Assertion Markup Language) uses XML-based assertions to communicate identity information between identity providers and service providers across domains.

  2. A user's access rights should be immediately revoked when they leave the organization. Which IAM process ensures this happens consistently?

    Answer: De-provisioning workflows

    De-provisioning workflows automate the removal of access rights, accounts, and credentials when a user's employment or role ends.

  3. Which access control model assigns permissions based on rules evaluated against environmental conditions such as time of day or location?

    Answer: ABAC

    Attribute-Based Access Control (ABAC) evaluates policies using attributes of the subject, resource, and environment — including contextual conditions like time or location.

  4. An organization wants to prevent a single administrator from having both the ability to create accounts and approve their own access requests. Which principle addresses this?

    Answer: Segregation of duties

    Segregation of duties (SoD) divides critical tasks between multiple people to prevent fraud and error by ensuring no single person controls an entire process.

  5. Which Kerberos component issues Ticket Granting Tickets (TGTs) after authenticating a user's credentials?

    Answer: Key Distribution Center

    The Key Distribution Center (KDC) contains the Authentication Server (AS) that validates credentials and issues TGTs used to request service tickets.

  6. What term describes the practice of using a single set of credentials to access multiple independent systems without re-authenticating?

    Answer: Single sign-on

    Single sign-on (SSO) allows users to authenticate once and gain access to multiple systems without entering credentials again for each application.

  7. Which biometric error rate represents the probability that an unauthorized user is incorrectly granted access?

    Answer: False Acceptance Rate

    The False Acceptance Rate (FAR) measures how often the biometric system accepts an unauthorized individual, representing a security failure.