Security and Access Control Flashcards
7 cards from real MDM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and Access Control flashcards as text
Which Informatica MDM API security mechanism requires callers to pass a session token obtained from an initial login call?
Answer: MDM Hub SIF session tokens
The MDM Hub Services Integration Framework (SIF) uses session tokens obtained via a login() call that must be passed with all subsequent API requests to authenticate the caller.
A security audit finds that multiple MDM Hub users share the same login credentials. What is the primary risk this creates?
Answer: Loss of individual accountability in audit logs and inability to enforce per-user access controls
Shared credentials prevent MDM audit logs from attributing changes to individual users and make it impossible to enforce per-user data filters or tailored privilege sets.
In Informatica MDM, what security consideration applies when using the Bulk Data Manager for large-scale data loads?
Answer: Bulk loads bypass all row-level security and data filters
Bulk data operations in MDM Hub typically bypass row-level data filters, so organizations must ensure that bulk load service accounts are tightly restricted and audited.
Which Informatica MDM security feature allows masking a field like date-of-birth so some users see the full value while others see only the year?
Answer: Separate packages with different field projections
Creating multiple packages — one with the full DOB field and one with only a partial or masked projection — and assigning package READ privileges to different roles achieves field-level access differentiation.
When Informatica MDM is integrated with an external identity provider via LDAP groups, how are LDAP groups typically mapped to MDM security?
Answer: LDAP group membership is mapped to MDM Hub roles through explicit configuration in the Hub Console
Administrators explicitly map LDAP groups to MDM Hub roles in the Hub Console security configuration, giving LDAP group members the privileges of the corresponding MDM role.
In Informatica MDM, which security practice should be applied to the MDM Hub's database service account to minimize risk?
Answer: Restrict the service account to only the specific schemas and operations MDM Hub requires
The MDM Hub database service account should follow least-privilege principles, having only the permissions needed to access CMX_SYSTEM and ORS schemas with the specific operations MDM requires.
What is the recommended approach for securing Informatica MDM SIF web service endpoints exposed to external consumers?
Answer: Place MDM SIF endpoints behind an API gateway or reverse proxy with TLS termination and network access controls
Best practice is to front MDM SIF endpoints with an API gateway or reverse proxy that enforces TLS, rate limiting, and network-level access controls in addition to MDM's own authentication.