Practice ISC Identity And Access Management Architecture questions with full explanations on every answer.
Start practicing
Identity And Access Management Architecture — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
In a SAML 2.0 federation architecture, the Service Provider (SP) returns a 403 error during the assertion consumption phase. After verifying the digital signature, what is the most likely cause?
2You are implementing Zero Trust Network Access (ZTNA) using Zscaler Private Access (ZPA). Which component is responsible for the actual interception and brokering of the connection between the user and the private application?
3When deploying HashiCorp Vault for secrets management, you need to implement a 'Dynamic Secrets' architecture for database access. Which workflow is correct?
4In a Zero Trust architecture, what is the primary role of a Policy Decision Point (PDP)?
5When designing a privileged access management (PAM) solution using CyberArk, you must ensure that privileged credentials are never exposed to the end-user workstation. Which feature facilitates this?
6You are configuring an AWS IAM Identity Center (successor to AWS SSO) environment. You need to provide temporary, elevated access to a developer for a specific account. Which mechanism provides the most granular architectural approach for this?
7You are deploying OIDC (OpenID Connect) for a web application. You need to prevent token replay attacks. Which claim should the application validate in the ID Token?
8You are designing an Azure AD (Entra ID) Conditional Access policy to restrict access to sensitive applications. You need to ensure that only compliant, managed devices can access the resource. Which Grant control must be configured?
9You are architecting a solution to mitigate 'Token Theft' in a Zero Trust environment. Which mechanism binds a token to a specific client instance?
10Which protocol is the industry standard for automating the exchange of user identity information between an Identity Provider and a Service Provider?
11When implementing FIDO2/WebAuthn for passwordless authentication, where does the private key reside?
12You are auditing an OAuth 2.0 implementation. You discover that the application uses the 'Implicit Grant' flow. Why is this considered an architectural security weakness?
13In a cloud architecture, what does the 'Principle of Least Privilege' (PoLP) imply regarding IAM roles?
14What is the primary architectural purpose of implementing Just-in-Time (JIT) access?
15You are implementing an IdP-initiated SSO flow. What is the primary architectural requirement for the SP?
16What is the purpose of 'Claims Transformation' in an Identity Provider?
17Which authentication factor is considered 'inherence'?
18You are securing a microservices architecture using mTLS. Which party is responsible for issuing the certificates that identify each service?
19In the context of the OAuth 2.0 Authorization Code flow, why is the 'client_secret' never sent to the user's browser?
20What is the primary function of an 'Identity Bridge' in a hybrid architecture?
21You are configuring an AWS IAM policy to allow a user to list S3 buckets only if they are connected from a specific IP range. Which policy element is required?
22What is the benefit of using 'Scoped Access Tokens' in an OAuth architecture?
23When using an API Gateway as a Policy Enforcement Point (PEP), where should the authorization decision logic be offloaded to ensure central governance?
24What is the primary role of an 'Attribute-Based Access Control' (ABAC) system compared to 'Role-Based Access Control' (RBAC)?
25In a SAML-based federation, what is the purpose of the 'RelayState' parameter?
26You are designing an IAM architecture for a global enterprise. You must ensure that PII is not transmitted in cleartext within identity tokens. What is the standard security requirement?
27What is the function of 'Token Introspection' in OAuth 2.0?
28You are troubleshooting an OIDC flow where the client fails to fetch the user information. What is the correct OIDC endpoint to call?
29What is the primary risk of 'Standing Privileges'?
30Which component in a Privileged Access Management (PAM) solution is responsible for 'Credential Rotation'?
31What is the primary architectural purpose of a 'Security Token Service' (STS) in a federated environment?
32When migrating to a Zero Trust architecture, what is the recommended approach for legacy applications that do not support modern authentication protocols (SAML/OIDC)?
33Which TWO security properties are provided by modern 'Passwordless' architectures?
34What is the purpose of 'JWT Validation' on a resource server?
35Which TWO factors are mandatory for a secure 'MFA' implementation?
36Which THREE components are involved in a standard OIDC authentication flow?
37Which TWO actions should be taken when designing a highly available IAM architecture?
38Which TWO risks are significantly mitigated by implementing a Privileged Access Management (PAM) vault?
39Which THREE criteria are typically evaluated by a Policy Decision Point (PDP) in a Zero Trust environment?
40Which THREE types of claims are typically included in a JSON Web Token (JWT)?
41Which TWO concepts are central to 'Federated Identity'?
42Which TWO components are critical for an identity-centric Zero Trust architecture?
43Which THREE mechanisms are commonly used to secure the 'Authorization Code' in an OAuth 2.0 flow?
44Which THREE features are essential for a modern IAM Lifecycle Management (LCM) system?
45Which TWO methods are used to prevent 'Token Replay' attacks in an OAuth/OIDC architecture?
46Which THREE attributes of a user session are typically monitored by a CASB (Cloud Access Security Broker)?
47Which THREE security mechanisms are recommended when using an API Gateway to handle authentication?
48Which TWO types of certificates are used in a standard mTLS implementation?
49Which THREE components are critical to ensuring secure 'Just-In-Time' (JIT) access?
50An ISSAP architect is configuring Azure AD (Entra ID) Conditional Access policies to enforce Zero Trust. The requirement is to ensure that users accessing sensitive applications are verified as compliant with Intune device status. Which assignment condition is required?
51An architect is designing an OAuth 2.0 implementation for a mobile application. To prevent authorization code injection attacks, which specific configuration must be enforced in the client registration?
52Which architectural principle is fundamental to implementing Zero Trust in a microservices environment?
53In a SAML 2.0 federation, an Identity Provider (IdP) is failing to authenticate users because the Service Provider (SP) cannot verify the assertion integrity. The SP requires the IdP to sign the assertion. What must be exchanged to solve this?
54A firm is deploying a Just-In-Time (JIT) access model using CyberArk. Which component architecture is required to perform privileged session recording while ensuring the vault is not directly exposed to the internet?
55An organization is migrating to SCIM (System for Cross-domain Identity Management) for automated provisioning. Which entity is responsible for receiving the provisioning request from the Identity Provider?
56You are designing an OIDC implementation. An application needs to obtain user profile information without including it in the ID Token to keep the token size small. Which endpoint should the application call?
57Which THREE features are essential for a robust Privileged Access Management (PAM) architecture that adheres to the principle of least privilege?
58Which THREE attributes should be evaluated when defining access policies in a modern Zero Trust Architecture?
59When designing a Federated Identity architecture using OIDC/SAML, which TWO security considerations are critical for the Relying Party (SP)?
The Identity And Access Management Architecture domain covers the key concepts tested in this area of the ISC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ISC domains — no account required.
The Courseiva ISC question bank contains 59 questions in the Identity And Access Management Architecture domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Identity And Access Management Architecture domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included