Font size
WorksheetsC8 Identity and Access Management 100q
Total questions: 100
Worksheet time: 2hrs 40mins
A healthcare organization issues smart badges to all staff members to log into workstations. What type of identity mechanism is being employed?
Biometrics
Hardware token
Federated identity
Smart card
In a university setting, students log in with a campus-wide credential that allows access to email, library databases, and learning portals. What identity concept is being used?
Role-based access control
Multifactor authentication
Single sign-on (SSO)
Discretionary access control
A company uses LinkedIn credentials to allow users to sign into their internal training platform. What identity federation technique is this?
Biometrics
Identity proofing
Federated login
Role-based delegation
While onboarding, an employee is asked to provide a government-issued ID and utility bill. What process is taking place?
Provisioning
Federation
Identity proofing
Authorization
What identity type describes the unique characteristics and records associated with a user in a system?
Role
Subject
Entity
Digital identity
An employee’s access is automatically revoked once they leave the company. What process ensures this occurs?
Access logging
Credential rotation
Deprovisioning
Authorization
What identity model requires credentials to be validated by a third-party identity provider across multiple domains?
Local authentication
Role-based access
Federated identity
SSO
Which of the following best defines an identity as used in Identity and Access Management (IAM)?
A username and password pair
A unique representation of a subject including attributes
An assigned role
A device on the network
Which of the following is NOT an example of identity data?
Fingerprint scan
Group membership
File ownership
Date of birth
What is the purpose of a directory service in identity management?
To detect malware on user accounts
To store and retrieve identity-related data
To control encryption keys
To monitor network traffic
In which scenario would identity federation be most useful?
Allowing a user to log into a workstation using a PIN
Allowing contractors to log into a corporate system using their own organization’s credentials
Assigning access rights to files
Encrypting database records
What is the primary concern if an identity provider (IdP) is compromised in a federated identity system?
The user cannot access shared folders
All authentication and linked services are at risk
The domain name might change
Role-based access must be reconfigured
What identity principle ensures users are only given the minimum levels of access necessary?
Least privilege
Role-based access
Multifactor authentication
Authorization mapping
Which of these best describes the relationship between an identity provider and a relying party?
Peer-to-peer
Accessor-owner
Authenticator-verifier
Provider-consumer
Which format is commonly used in SAML-based federated identity systems?
XML
CSV
JSON
SQL
A company requires employees to authenticate via a QR code tied to their mobile identity app. What authentication mechanism is being used?
Knowledge-based
Token-based
Biometric
Certificate-based
Why is an identity lifecycle important in IAM?
To track user purchases
To ensure physical security of devices
To manage access across hire-to-retire processes
To enforce encryption on stored data
What identity concept helps define access based on a user’s attributes like department or job function?
DAC
ABAC
MAC
RBAC
What component of IAM verifies that a person is who they claim to be?
Authorization
Provisioning
Authentication
Group policy
An organization links its cloud file storage service to its internal Active Directory for login purposes. This is an example of:
Biometrics
Identity federation
Smart token authentication
Device-based trust
Which of the following best supports the concept of identity assurance?
Length of a password
Identity proofing
Logging user keystrokes
Providing a VPN
A hospital uses a system where a staff member’s access is dictated by their job (doctor, nurse, admin). This is an example of:
DAC
RBAC
ABAC
MAC
What is typically the first phase in the identity lifecycle?
Revocation
Authentication
Proofing
Onboarding
What document formally outlines how identities are issued, validated, and managed?
SLA
Certificate of trust
IAM policy
Token agreement
Which of the following best describes the goal of IAM in an enterprise?
Encrypting employee emails
Tracking employee time cards
Ensuring proper access to resources based on verified identity
Blocking access to websites
An organization requires employees to use a password and a fingerprint to access a secure database. What is this an example of?
Single-factor authentication
Password complexity
Multifactor authentication
Role-based access control
Which of the following is considered something you have in an authentication context?
Retina scan
Password
PIN
Smart card
What protocol is typically used in Kerberos authentication?
CHAP
NTLM
LDAP
Ticket Granting Tickets (TGT)
A system uses a challenge-response mechanism to authenticate users without sending passwords over the network. What protocol is likely being used?
Kerberos
CHAP
LDAP
OAuth
What is the main purpose of RADIUS in an authentication environment?
Password complexity enforcement
Password expiration and history policy
Single sign-on configuration
Biometric fallback policy
What type of access control model assigns permissions based on job titles or functions?
MAC
RBAC
DAC
ABAC
Which factor is used when authentication is based on retinal scanning?
Something you know
Something you have
Something you are
Somewhere you are
An online banking application sends a one-time code via SMS in addition to a password. What is this technique called?
OAuth
Two-factor authentication
SAML
Identity federation
What does the principle of least privilege help prevent?
System crashes
Credential reuse
Unauthorized access
Redundant logging
In OAuth 2.0, what is the purpose of the access token?
Authenticate users
Define password requirements
Grant limited access to user resources
Replace multifactor authentication
What protocol does Microsoft Active Directory commonly use for user authentication?
SAML
LDAP
Kerberos
TACACS+
What type of access control gives the "owner" of a file the discretion to decide who else can access it?
MAC
ABAC
DAC
RBAC
Which of the following best describes TACACS+?
Decentralized access control
Biometric encryption protocol
Centralized AAA protocol used by Cisco
Token generation service
A company uses a fingerprint scanner on its employee entrance and an ID badge swipe. What best describes this approach?
Dual control
Two-factor authentication
Single sign-on
Biometric access override
In SAML, what is the system that provides authentication and issues assertions called?
Relying Party
Service Provider
Authorization Agent
Identity Provider
What is the primary goal of authorization in access management?
Prevent physical access to servers
Verify user identity
Grant appropriate access to resources
Rotate encryption keys
Which of the following is NOT considered a secure authentication method?
Plaintext passwords
Kerberos
Certificate-based authentication
Biometrics
Which access model is used when access rights are granted based on user and environmental attributes such as time of day or location?
RBAC
DAC
ABAC
MAC
A cloud application uses SAML to allow users to log in using their enterprise credentials. What is this called?
OAuth redirection
Federation
Token relay
RBAC proxy
Which component ensures only authorized users can view or modify resources after logging in?
SSO
Federation
Authorization
Authentication
What mechanism allows users to authenticate once and gain access to multiple systems without re-entering credentials?
LDAP chaining
Single Sign-On (SSO)
RBAC linking
OAuth tunneling
Which of these protocols is used to enable web-based Single Sign-On (SSO)?
OAuth
CHAP
SAML
TACACS
In a certificate-based authentication system, what is required on the client side?
Username only
Private key
Browser plugin
Security question
Which term describes a system that both authenticates users and decides whether they are allowed to access specific resources?
Identity Broker
Access Gateway
AAA System
Endpoint Protector
Which authentication method involves using a changing numeric code generated by a physical or software token?
LDAP
TOTP
OAuth
SAML
What authentication factor is used when logging in with a USB security key?
Something you know
Something you are
Something you have
Something you do
What protocol uses tokens and allows one application to access resources on another application without exposing passwords?
Kerberos
OAuth
SAML
RADIUS
Which of the following is NOT considered a secure method of password storage?
Hashing with bcrypt
MD5 without salting
SHA-256 with salting
Argon2id hashing
What biometric method analyzes the unique pattern of ridges and valleys on a person’s finger?
Iris scan
Facial recognition
Fingerprint recognition
Retinal scan
What is a key benefit of using biometric authentication?
Passwords are no longer needed
Biometrics are non-repudiable
Multi-device access is blocked
It guarantees anonymity
A company implements facial recognition at entry points. What type of authentication method is this?
Token-based
Knowledge-based
Biometric
Location-based
Which protocol is most commonly used in VPN authentication and can carry a variety of methods, including certificates?
LDAP
EAP
OAuth
TOTP
What is HOTP primarily used for?
Encrypting network traffic
Granting authorization to users
One-time password generation based on a counter
Biometric scanning
Which is an example of knowledge-based authentication?
Answering a security question
Scanning a retina
Receiving an SMS code
Using a hardware token
Which technology is often used to implement certificate-based authentication?
SAML
TOTP
Public Key Infrastructure (PKI)
OAuth2
Why is biometric authentication considered more secure than passwords?
Biometrics change regularly
They are stored in plaintext
They cannot be guessed or easily shared
They are updated monthly
Which method can be used to verify that a password was not altered in transit?
Salting
Hashing
Tunneling
Signing
What authentication protocol supports single sign-on and works across different domains?
NTLM
Kerberos
EAP-TLS
LDAP
What makes TOTP more secure than HOTP in many environments?
TOTP codes never expire
TOTP doesn’t require a token
TOTP is based on time, limiting the window of validity
HOTP is based on a private key
A hardware security module (HSM) is used for what authentication purpose?
Biometric scanning
Credential revocation
Secure cryptographic key storage and operations
Password generation
Which type of authentication requires a certificate stored on the device to verify user identity?
Kerberos
LDAP
Certificate-based
Biometric
Which of the following is most likely to help protect against credential stuffing attacks?
SMS-based authentication
TOTP
Account lockout policies
Static passwords
Which biometric method is often considered the most accurate?
Voice recognition
Iris scan
Facial recognition
Fingerprint scan
An enterprise uses certificates installed on laptops to authenticate to Wi-Fi. What is this called?
TOTP login
RADIUS relay
Certificate-based authentication
Biometric access
A user's identity is verified by swiping a badge and entering a PIN. What type of authentication is this?
Single-factor
Multifactor
Biometric-only
Password-less
What makes OAuth 2.0 preferable for mobile app authentication?
It uses biometric tokens
It encrypts traffic using EAP
It grants limited access without sharing user credentials
It relies on session cookies
Which method uses a time-based algorithm and shared secret key for code generation?
HOTP
TOTP
LDAP
RBAC
A certificate is revoked due to suspected compromise. Where is this status made publicly available?
LDAP directory
DNS resolver
CRL (Certificate Revocation List)
RADIUS server
Which authentication method offers the highest resistance to phishing?
Knowledge-based
Password-based
Smart cards
FIDO2 security keys
A new employee is assigned a user account with access to specific folders and email systems. What process is this an example of?
Federation
Provisioning
Authorization
Delegation
What is the primary purpose of implementing account expiration for temporary accounts?
To restrict login hours
To reduce password complexity
To automatically remove access after a defined period
To enforce password changes
What type of account should a system administrator use for everyday tasks like checking email?
Domain admin account
Root account
Guest account
Standard user account
Which of the following is considered a privileged account?
Domain user
Guest user
System service account
Administrator account
What process ensures inactive or orphaned accounts are detected and removed?
Account lifecycle management
Credential rotation
Access control modeling
Identity proofing
Which of the following is a best practice for managing default accounts on systems?
Keep them enabled for troubleshooting
Share the credentials with all administrators
Disable or rename them if not in use
Use them only during business hours
A user leaves an organization, but their account is not disabled. What type of risk does this represent?
Insider threat
Compliance gap
Account hijacking
Orphaned account
What type of account is typically used by software to run background processes?
User account
Administrator account
Service account
Guest account
A system is configured to require re-approval of accounts every 90 days. What is this practice called?
Account reconciliation
Access certification
Deprovisioning
Authentication
Which feature allows tracking who accessed or modified a specific user account?
SAML
Authentication log
Access control list
Account audit trail
Why should administrator accounts not be used for daily tasks?
They can be shared between users
They bypass antivirus software
They expose systems to elevated risk if compromised
They expire every 30 days
A developer is given a separate account with elevated privileges to deploy applications. This is an example of:
Role escalation
Just-in-time access
Privilege separation
Group nesting
What term describes an account that is shared between multiple users?
Privileged account
Shared account
Service account
Root account
A manager notices a former employee’s account is still active in HR systems. What control failed?
Role-based access control
Account deprovisioning
Access approval
Authentication
What is the main security concern with using shared accounts?
They generate too many logs
Users forget their passwords
They lack individual accountability
They cost more to manage
What is the purpose of enforcing unique user IDs?
Prevent phishing
Enable password reuse
Support non-repudiation
Block admin access
What is the benefit of implementing a role-based account model?
Easier for users to bypass controls
Simplifies permission assignments
Eliminates need for authentication
Reduces need for backups
An attacker gains access to a disabled employee account. What principle was violated?
Defense in depth
Least privilege
Access control
Account lifecycle management
Which setting can help detect if multiple logins are occurring from one account simultaneously?
Account lockout
Login concurrency restriction
Session timeout
Password age
A contractor is hired for 30 days. What type of account should be created?
Service account
Administrator account
Temporary account
Guest account
What should happen to accounts of users who go on long-term leave?
They should be deleted immediately
Set to guest mode
Temporarily disabled or suspended
Made shared with a peer
Which of the following is NOT a common type of account?
Guest
Service
Audit
Root
Why should service accounts be monitored closely?
They use biometric data
They often have elevated, non-expiring privileges
They rotate passwords automatically
They are temporary by design
What control helps prevent misuse of accounts after termination?
Password complexity
Account lockout policy
Timely deprovisioning
TOTP enforcement
A financial institution requires approval from two managers to create new high-level user accounts. What is this control?
Principle of least privilege
Mandatory access control
Dual control
Role-based access
What type of access control relies on labels such as "Confidential" or "Top Secret"?
RBAC
DAC
MAC
ABAC
