Security Architecture & IAM Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture & IAM flashcards as text
In OAuth 2.0, which grant type is MOST appropriate for a server-to-server API integration where no user interaction is involved?
Answer: Client Credentials
The Client Credentials grant type is designed for machine-to-machine authentication where the client acts on its own behalf without delegating user permissions.
Which identity governance capability ensures that toxic combinations of access rights are not granted to the same individual?
Answer: Separation of duties (SoD) policy enforcement
SoD policy enforcement detects and prevents scenarios where a single user holds conflicting permissions that together could enable fraud or bypass controls.
A security architect is evaluating trust levels in a multi-cloud environment. What is the purpose of a Cloud Access Security Broker (CASB)?
Answer: Providing visibility, compliance, and threat protection for cloud service usage
A CASB sits between users and cloud services to enforce security policies, provide visibility into shadow IT, ensure compliance, and detect threats across SaaS, IaaS, and PaaS.
During a security architecture review, a CSI discovers that service accounts share the same credentials. What is the PRIMARY risk this creates?
Answer: Inability to attribute actions to specific services, complicating breach investigation and containment
Shared credentials prevent attribution of individual service actions, make credential rotation difficult, and mean that a single compromised credential affects multiple services simultaneously.
What is the security significance of certificate pinning in mobile application architecture?
Answer: It prevents man-in-the-middle attacks by binding the app to a specific certificate or public key
Certificate pinning embeds the expected server certificate or public key in the app, so even a rogue certificate from a trusted CA will be rejected, preventing interception.
In a defense-in-depth security architecture, what layer does data classification PRIMARILY support?
Answer: Data security layer — enforcing controls proportionate to data sensitivity
Data classification identifies sensitivity levels, which drives the data security layer's encryption requirements, access controls, retention policies, and handling procedures.
An enterprise is migrating to passwordless authentication. Which combination of factors meets FIDO2 WebAuthn requirements?
Answer: Platform authenticator or roaming authenticator with cryptographic user verification
FIDO2 WebAuthn uses public-key cryptography with authenticators (platform built-in or external roaming) that perform user verification locally, never transmitting secrets to the server.