← All CSI Flashcard Decks

Security Architecture & IAM Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Architecture & IAM flashcards as text
  1. A system integrator is designing IAM for a healthcare system that must comply with HIPAA. Which access control model BEST aligns with the minimum necessary principle?

    Answer: Role-Based Access Control (RBAC) with least-privilege role definitions

    RBAC with carefully scoped roles ensures clinical staff access only the PHI required for their specific function, directly implementing HIPAA's minimum necessary standard.

  2. Which security architecture component is responsible for continuously verifying device health posture before allowing network access under a Zero Trust model?

    Answer: Network Access Control (NAC) with posture assessment

    NAC with posture assessment continuously checks device compliance — OS patch level, endpoint protection status, and configuration — as a condition of granting or maintaining network access.

  3. When designing an IAM architecture for a microservices application, which approach BEST secures service-to-service communication?

    Answer: Mutual TLS (mTLS) with short-lived certificates issued by a service mesh

    mTLS with a service mesh ensures both parties authenticate cryptographically, certificates are short-lived to limit breach impact, and the mesh enforces policy without modifying application code.

  4. What is the primary security benefit of implementing an Identity Broker in a hybrid cloud architecture?

    Answer: Centralizing trust translation between multiple identity providers and service providers

    An identity broker decouples service providers from specific IdPs by translating and aggregating identity assertions, enabling flexible federation without requiring each SP to integrate with every IdP directly.

  5. A CSI is asked to evaluate the security of a JWT-based authentication system. Which vulnerability is MOST critical to check for?

    Answer: Accepting tokens with the 'alg' header set to 'none'

    Accepting tokens with alg=none means the server skips signature verification entirely, allowing attackers to forge arbitrary tokens by simply setting the algorithm to none.

  6. Which IAM architecture pattern enables an organization to maintain control over identity while allowing users to access resources at partner organizations?

    Answer: Identity federation using a hub-and-spoke model with the organization as the Identity Provider

    In hub-and-spoke federation, the organization acts as the IdP and asserts identity to partner Service Providers via standards like SAML or OIDC, maintaining control over authentication.

  7. When architecting a secrets management solution for a CI/CD pipeline, what is the MOST important security control to implement?

    Answer: Dynamic secret generation with short TTLs and audit logging of every secret access

    Dynamic secrets generated on-demand with short time-to-live values minimize exposure windows, while audit logging provides accountability for every credential issuance event.