Security Architecture & IAM Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture & IAM flashcards as text
An organization's security architecture uses security zones. What is the CORRECT traffic flow for a user accessing an internal application from the internet?
Answer: Internet → DMZ (reverse proxy/WAF) → Internal application zone
Traffic should pass through the DMZ where a reverse proxy or WAF inspects and terminates external connections before forwarding authenticated requests to the protected internal application zone.
Which cryptographic concept ensures that a sender cannot later deny having sent a message?
Answer: Non-repudiation via digital signatures
Digital signatures use the sender's private key, which only they possess, creating cryptographic proof of authorship that the sender cannot credibly deny later.
In an enterprise deploying OIDC for single sign-on, what is the purpose of the ID token?
Answer: Conveying the authenticated user's identity claims to the client application
The OIDC ID token is a signed JWT containing identity claims (sub, name, email, etc.) that the client uses to understand who the authenticated user is, separate from the access token used for API calls.
A CSI is hardening an Active Directory environment. Which configuration MOST reduces the attack surface for credential theft?
Answer: Enabling Protected Users security group and disabling NTLM where possible
The Protected Users group forces Kerberos-only authentication and prevents credential caching, while disabling NTLM removes the legacy authentication protocol most exploited in pass-the-hash attacks.
When evaluating an IAM solution for regulatory compliance, which capability directly supports SOX requirements for financial systems?
Answer: Automated access certification and SoD enforcement with documented evidence
SOX requires evidence that access to financial systems is appropriately controlled; automated access certification reviews and SoD enforcement generate the audit evidence regulators require.
What is the security architecture implication of using long-lived access tokens in an OAuth 2.0 implementation?
Answer: Extended window of opportunity for attackers if a token is stolen or leaked
Long-lived access tokens remain valid for extended periods, meaning a stolen token gives an attacker prolonged unauthorized access; short-lived tokens with refresh token rotation mitigate this risk.
Which security control is MOST effective at detecting compromised privileged credentials being used from an unusual location?
Answer: User and Entity Behavior Analytics (UEBA) with risk-based adaptive authentication
UEBA establishes behavioral baselines and flags anomalies like unusual login locations, times, or access patterns, then triggers step-up authentication or blocks access when risk thresholds are exceeded.