Map each scenario to the correct identity control: identify the attack (golden ticket, pass-the-hash), select the access model matching the described ownership, and choose the OAuth grant fitting the client type. The single most important thing: separate authentication from authorization before answering.
Start practicing
Identity and Access Management — choose a session length
Free · No account required
Domain overview
Identity and Access Management covers authentication, authorization, and identity lifecycle controls: Kerberos, federation, OAuth/OIDC, SAML, access control models, and provisioning. CISSP tests your ability to select the right control for a scenario, distinguish authentication from authorization, and recognize attacks like Kerberos ticket forgery, credential stuffing, and privilege escalation through misconfigured trust.
Exam objectives
Kerberos flows: AS, TGT, TGS, service tickets, and KRBTGT golden ticket forgery
Access control models: DAC, MAC, RBAC, ABAC, and rule-based authorization decisions
OAuth 2.0 grant types, OpenID Connect, SAML assertions, and PKCE for public clients
Identity lifecycle: provisioning, deprovisioning, federation, SSO, and privileged access management
Confusing authentication (proving identity) with authorization (granting permissions), which flips scenario answers.
Choosing MAC when the scenario describes a resource owner setting permissions, which is DAC.
Picking the implicit or password grant for mobile apps instead of authorization code with PKCE.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which authentication factor type is a smart card?
2In Kerberos authentication, which component issues a Ticket Granting Ticket (TGT) after verifying the user's credentials?
3An attacker who has compromised the Kerberos Key Distribution Center (KDC) could forge a Ticket Granting Ticket (TGT) to impersonate any user. This type of attack is known as:
4Which OAuth 2.0 grant type is recommended for a public client (e.g., single-page application) that cannot securely store a client secret?
5OpenID Connect (OIDC) extends OAuth 2.0 primarily by adding which capability?
6An organization is implementing identity management and wants to ensure that when an employee leaves, all access is promptly revoked. Which process is most directly responsible for removing accounts and access rights for a leaver?
7A security analyst is reviewing access rights and discovers an active account belonging to a former employee who left six months ago. This is an example of:
8In a Privileged Access Management (PAM) solution, which feature provides temporary elevation of privileges for specific tasks, reducing the risk of standing privileges?
9In LDAP, what does the Distinguished Name (DN) uniquely identify?
10Which access control model allows the owner of a resource to determine who can access it and what permissions they have?
11A security policy requires that a user cannot have both the ability to create purchase orders and approve invoices. This is an example of:
12Which of the following is an example of a Type 2 authentication factor?
13A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implemented?
14Which protocol is specifically designed for authorization and not authentication, often using grant types like authorization code and client credentials?
15In an OAuth 2.0 authorization code flow with PKCE, what is the primary purpose of the code verifier and code challenge?
16An organization wants to implement single sign-on across multiple web applications using an XML-based protocol that supports identity provider (IdP) and service provider (SP) initiated flows. Which technology should they choose?
17An employee leaves the company, and their user account is not disabled. This creates a security risk known as:
18Which principle ensures that a user is granted only the permissions necessary to perform their job functions?
19An organization wants to provide just-in-time administrative access to servers, with session recording and password vaulting. Which solution is best suited?
20An LDAP distinguished name (DN) includes the attribute 'CN=John Doe,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?
21Which access control model bases decisions on attributes of the user, resource, and environment, and can use Boolean logic to define policies?
22A security analyst is reviewing access controls for a financial application. Which TWO of the following are considered best practices for preventing fraud? (Select TWO.)
23An organization is implementing a Privileged Access Management (PAM) solution. Which THREE of the following are common features of PAM? (Select THREE.)
24Which of the following is an example of a Type 1 authentication factor?
25In Kerberos authentication, what is the purpose of the Ticket Granting Ticket (TGT)?
26A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?
27In SAML 2.0, which component is responsible for authenticating the user and generating an assertion?
28An organization wants to enable single sign-on (SSO) across multiple web applications using an XML-based protocol that supports browser redirect flows. Which technology is most appropriate?
29In OAuth 2.0, which grant type is recommended for a native mobile application that cannot securely store a client secret, and uses PKCE?
30Which of the following is a process that ensures users periodically confirm they still need access to systems and data?
31A financial application requires two employees to authorize a wire transfer. Which principle does this implement?
32An organization implements Privileged Access Management (PAM) and wants to reduce the risk of standing privileges. Which approach grants temporary elevated access only when needed?
33In LDAP, which attribute uniquely identifies an entry within the directory information tree?
34Which access control model assigns permissions based on a user's job function?
35A security administrator is reviewing potential risks associated with orphaned accounts. Which TWO of the following are risks of orphaned accounts?
36Which THREE of the following are components of a Privileged Access Management (PAM) solution?
37Which TWO of the following are differences between OAuth 2.0 and OpenID Connect (OIDC)?
38A security architect is designing an authentication system for a healthcare application that requires strong security. The system will use a password and a one-time passcode sent via SMS. How many authentication factor types are being used?
39During a Kerberos authentication process, the client receives a Ticket Granting Ticket (TGT) from the Authentication Server (AS). Later, the client presents the TGT to the Ticket Granting Server (TGS) to request a service ticket. Which of the following best describes the purpose of the TGT?
40An organization implements Single Sign-On (SSO) using SAML 2.0. A user attempts to access a cloud application (Service Provider) but is not authenticated. The Service Provider redirects the user to the Identity Provider (IdP) for authentication. Which type of SAML flow is this?
41A developer is implementing OAuth 2.0 for a mobile app (public client) that needs to access a user's data from a third-party API. To mitigate the authorization code interception attack, which OAuth 2.0 extension should be used?
42A financial institution requires that no single employee can approve a transaction and also reconcile the account. This is an example of which security principle?
43Which of the following is a lightweight directory access protocol used for accessing and maintaining distributed directory information?
44An organization discovers that a former employee's account is still active and has been used to access sensitive data. This is an example of which type of risk?
45Which TWO of the following are characteristics of a Privileged Access Management (PAM) solution? (Choose two.)
46Which TWO of the following are OAuth 2.0 grant types? (Choose two.)
47A security analyst is performing an access review. Which THREE of the following are best practices for user access recertification? (Choose three.)
48In the context of identity management, which TWO of the following are risks associated with orphaned accounts? (Choose two.)
49An organization is implementing OpenID Connect (OIDC) for authentication. Which THREE of the following are components of OIDC? (Choose three.)
50Which TWO of the following are examples of Type 3 authentication factors? (Choose two.)
51A healthcare organization uses a federated identity provider (IdP) to authenticate clinicians into a third-party electronic health record (EHR) application acting as a SAML 2.0 Service Provider (SP). The security team wants to reduce the risk that a stolen IdP session cookie could be replayed against the EHR. Which SAML 2.0 control should the team implement to bind the assertion to the authenticated browser session and limit replay?
52A multinational bank must enforce least privilege across 4,000 roles that change frequently as employees move between trading, compliance, and IT functions. Auditors found that access reviews are performed manually and that role definitions drift from actual job duties. The identity team proposes a role mining and management program. Which approach best aligns with identity and access management governance objectives while reducing role explosion?
53A financial services firm is deploying a customer-facing mobile banking app and wants to delegate limited access to account balances and transaction history to third-party budgeting apps without sharing the customer's banking credentials. The security architect must select controls that implement this delegation securely. (Choose two.)
Map each scenario to the correct identity control: identify the attack (golden ticket, pass-the-hash), select the access model matching the described ownership, and choose the OAuth grant fitting the client type. The single most important thing: separate authentication from authorization before answering.
The Courseiva CISSP question bank contains 53 questions in the Identity and Access Management domain, covering the 13% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Identity and Access Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included