Identity and Access Management Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity and Access Management flashcards as text
Which type of token used in OAuth 2.0 / OIDC contains encoded claims about the user and can be validated without contacting the authorization server?
Answer: JSON Web Token (JWT)
JWTs are self-contained tokens that embed claims as a signed JSON payload, allowing resource servers to validate them locally without a round-trip to the authorization server.
A CISSP candidate reviews a system where subjects access objects based on their security clearance and object classification labels. Which model is in use?
Answer: Bell-LaPadula
The Bell-LaPadula model enforces confidentiality by requiring that subjects only read at or below their clearance level (no read-up) and write at or above their clearance level (no write-down).
Which protocol extends RADIUS capabilities to support mobile and distributed network authentication with better reliability and security?
Answer: DIAMETER
DIAMETER is the successor to RADIUS, offering improved reliability (TCP/SCTP), better error handling, and enhanced security features for AAA services.
An attacker compromises a low-privilege account and uses it to request a service ticket for a high-privilege account, then cracks the ticket offline. What attack is this?
Answer: Kerberoasting
Kerberoasting exploits Kerberos by requesting service tickets for accounts with SPNs and cracking them offline to recover plaintext passwords.
Which access provisioning approach reduces risk by granting users only the minimum permissions required for their specific job responsibilities?
Answer: Least privilege
The principle of least privilege restricts user access rights to only what is necessary to perform their job, reducing the attack surface if the account is compromised.
Which identity management concept allows organizations to manage access across multiple domains without requiring shared infrastructure?
Answer: Federated identity management
Federated identity management enables trust relationships between separate organizations' identity systems, allowing users to access resources across domains using their home-organization credentials.
Which authentication method requires the user to prove identity using something they have (token) and something they know (PIN), but NOT a biometric factor?
Answer: Two-factor authentication
Two-factor authentication (2FA) combines exactly two distinct authentication factors; a hardware token plus a PIN uses 'something you have' and 'something you know'.