WorksheetsIdentity and Access Management Quiz
Total questions: 44
Worksheet time: 33mins
What is the primary purpose of Identity and Access Management (IAM)?
To back up organizational data
To design IT infrastructure
To control who can access what within a digital system
To monitor employee work hours
In IAM, what does the term "identity" refer to?
A user's job performance score
The digital information that uniquely identifies a user
The list of passwords a user owns
The name of the IT department
Why is it important for identity and access to work together in IAM?
So that users can access every system freely
To avoid having to create user profiles
Because identity confirms who a person is, and access determines what they can do
To automatically generate usernames for all employees
What is one key reason organizations use IAM systems instead of managing access manually?
It increases employee salaries
It replaces all human decision-making
It allows users to bypass passwords
It automates access control and reduces security risks
What does the first "A" in the AAA framework stand for, and what does it involve?
Authorization; allowing access to apps
Authentication; verifying a user's identity
Accounting; tracking financial activities
Access; granting all system rights
Which best describes the Principle of Least Privilege?
Allowing users access to everything at all times
Giving users access only to the data they request
Granting users only the access necessary for their job and nothing more
Letting users decide their own access levels
What is the main goal of the "Accounting" part of AAA in IAM?
To calculate user salaries
To determine user satisfaction
To log and monitor user activities for auditing and security purposes
To manage financial reports
What does the Zero Trust model emphasize in an IAM strategy?
Granting full trust to insiders only
Always verifying users and devices, even those inside the network
Trusting users who pass the authentication check
Never allowing access to sensitive systems
What are the three main phases of the identity lifecycle in IAM?
Creation, Promotion, Demotion
Birth, Growth, Death
Joiner, Mover, Leaver
Sign-up, Login, Logout
Which of the following is considered a "Something You Have" authentication factor?
Password
Fingerprint
Smartphone or security token
Typing speed
What is the key benefit of Multi-Factor Authentication (MFA)?
It replaces all other forms of authentication
It allows users to log in without a password
It combines multiple factors to strengthen security
It enables remote login without approval
How does Single Sign-On (SSO) improve user experience and security?
By letting users create multiple accounts for each system
By allowing users to log in once and access many systems
By requiring complex passwords for every login
By sending login alerts to users daily
Which access control model grants permissions based on a user’s job title or role?
ABAC
PBAC
RBAC
MAC
What is a key advantage of Attribute-Based Access Control (ABAC)?
It gives resource owners full control over access
It’s the most secure model available
It adjusts access based on user attributes like location, department, and employment type
It allows access based solely on login time
In the Policy-Based Access Control (PBAC) model, which of the following would typically be a rule for granting access?
User’s job title
User’s login time and device type
User’s fingerprint
User’s favorite app
Which access control model uses classification labels like “Public,” “Confidential,” and “Secret,” and requires matching user clearance?
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
What is the key difference between a role and an entitlement in IAM?
Roles are temporary, while entitlements are permanent
Roles define general access needs, entitlements specify exact permissions within systems
Roles are for contractors, entitlements for employees
Roles are always defined by the user, entitlements by the system
How do role hierarchies improve access management in an organization?
They remove the need for any entitlements
They allow senior roles to inherit access from junior roles, reducing complexity
They limit user access to a single application
They prevent access from being updated automatically
What does mapping entitlements to business functions help an organization achieve?
Lower internet usage
Increased hardware performance
Alignment of user access with actual job responsibilities
Elimination of role-based access
Which principle is upheld when access is reviewed and adjusted after a promotion or role change?
First-Come, First-Served
Principle of Least Privilege
Open Access Policy
Maximum User Flexibility
What is the primary purpose of an Access Request System (ARS)?
To track employee attendance
To allow users to request special or temporary access securely and efficiently
To manage employee salaries
To update users’ job descriptions
In a “Series Approval” workflow, how is access approved?
All approvers approve at the same time
Each approver reviews the request one after the other
Only the application owner must approve
The system auto-approves all requests
What role does a “Default Approver” play in the ARS process?
Approves requests only on weekends
Is used in high-risk request approvals only
Acts as the fallback approver when no specific manager is listed
Approves only access to public data
What happens in an “Escalation After Timeout” scenario?
The user must resubmit their request
The request is forwarded to a backup approver if it isn’t acted upon in time
The request is automatically denied
The user gets temporary access immediately
What is the primary goal of Segregation of Duties (SoD) in IAM?
To prevent a person from having a toxic combination of access that could enable fraud or misuse
To ensure everyone has access to all systems
To limit system downtime
To reduce the number of job roles in an organization
What is a “toxic combination” in the context of SoD?
A mix of incompatible job titles
A user who has access to too many applications
Two or more permissions that are safe separately but risky when combined
A conflict between an employee and their manager
How can organizations enforce SoD effectively?
By allowing each department to set its own rules
By requiring users to manually track their own entitlements
By using IAM systems to automatically detect and block risky access combinations
By limiting employees to only one role
Which of the following is a way AI helps enhance SoD monitoring?
It deletes old user accounts
It performs behavior monitoring and peer comparisons to flag unusual access requests
It updates user passwords every day
It removes all access if a risk is detected
In the context of IAM, what is the role of Governance?
Catching hackers through firewall rules
Defining access rules and ensuring they align with business needs
Approving vacation requests
Resetting user passwords
Which of the following best defines "risk" in IAM?
A list of user passwords
The number of users in an organization
The chance of a data breach, fraud, or operational failure
The amount of storage used in cloud servers
Why is compliance important in an IAM program?
To speed up employee onboarding
To ensure access rules are being followed and regulatory requirements are met
To make sure everyone has equal access
To limit access to internal staff only
Which of the following is an example of an external compliance framework?
JavaScript
AWS
GDPR
SQL
What is the main purpose of access certifications in IAM?
To train new employees on IAM tools
To promote users to higher roles
To review and verify that users only have the access they need
To generate monthly performance reports
Which type of certification campaign would focus on verifying who has access to a specific application?
Role Campaign
Team Campaign
Application Campaign
Entitlement Campaign
How often are certifications typically conducted for high-risk roles like system administrators?
Annually
Monthly
Once at onboarding
Every five years
Which of the following is a key benefit of regular certification campaigns?
Encouraging users to request more access
Maintaining security and compliance by removing unnecessary privileges
Allowing access to sensitive systems without review
Simplifying password policies
What is the main purpose of a SaaS IAM connector?
To store passwords in the cloud
To monitor internet usage
To bridge cloud IAM systems with on-premises resources like Active Directory
To remove old user accounts automatically
Which IAM tool uses a Virtual Appliance (VA) to connect cloud IAM with local systems?
Azure AD
SailPoint
Okta
Google Workspace
What makes Saviynt Connect 2.0 (SC2.0) notable from a security perspective?
It uses public IPs for inbound communication
It creates a secure, outbound SSL tunnel without needing inbound ports
It requires admin passwords to be stored in plain text
It only works on Windows servers
What is one key benefit of using a hybrid IAM model with connectors?
It removes the need for cloud services
It allows centralized identity management across both cloud and on-prem environments
It limits user access to local networks only
It replaces the need for Active Directory
Which method does an IAM system typically use to grant access based on attributes like department, location, or role?
Discretionary Access Control (DAC)
Manual Role Assignment
Attribute-Based Access Control (ABAC)
Static Permissions List
What IAM feature allows a user to access multiple applications after a single successful login?
Password Reset Tool
Credential Vault
Single Sign-On (SSO)
Session Timeout
What should an IAM system do when an employee goes on extended leave?
Revoke all access permanently
Temporarily restrict access to sensitive systems
Require daily password changes
Lock the user out of all systems immediately
What is the key IAM process that ensures all user access is removed after an employee leaves the organization?
Role reassignment
Access certification
De-provisioning and account reconciliation
Password policy enforcement
