Security Architecture & IAM Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture & IAM flashcards as text
Which IAM concept ensures that a user's access rights are automatically revoked when they change roles within an organization?
Answer: Privilege creep prevention through role recertification
Role recertification processes periodically review and revoke accumulated access rights that no longer match a user's current role, preventing privilege creep.
In a Zero Trust Architecture, what is the primary function of a Policy Decision Point (PDP)?
Answer: Evaluating access requests against policy and issuing authorization decisions
The PDP evaluates each access request against defined policies and context attributes, then issues allow or deny decisions to the Policy Enforcement Point.
An organization wants to federate identity between their on-premises Active Directory and a cloud SaaS provider. Which protocol is MOST appropriate?
Answer: SAML 2.0
SAML 2.0 is the standard protocol for federated identity across organizational boundaries, enabling single sign-on between enterprise identity providers and cloud SaaS applications.
What distinguishes attribute-based access control (ABAC) from role-based access control (RBAC)?
Answer: ABAC evaluates multiple contextual attributes at runtime while RBAC grants access based on predefined roles
ABAC makes access decisions by evaluating combinations of user, resource, and environmental attributes at runtime, enabling much finer-grained control than static RBAC role assignments.
Which security architecture pattern places authentication and authorization logic at the edge of the network, before traffic reaches backend services?
Answer: API gateway with OAuth 2.0 token validation
An API gateway acts as the perimeter enforcement point, validating OAuth 2.0 tokens and enforcing authorization policies before requests reach microservices or backend systems.
A CSI is designing a privileged access management (PAM) solution. Which capability is MOST critical for reducing insider threat risk?
Answer: Session recording and just-in-time privilege elevation
Session recording provides audit trails of privileged activity, while just-in-time elevation minimizes the window of exposure by granting elevated rights only when needed.
When implementing PKI for an enterprise, what is the recommended approach for protecting the Root CA private key?
Answer: Keep it offline in a Hardware Security Module (HSM) in a physically secured facility
The Root CA key should be kept offline in an HSM within a physically secured, access-controlled facility to prevent compromise since it is the ultimate trust anchor for the entire PKI.