Courseiva

CCNA Identity and Access Management Questions

53 questions · Identity and Access Management · All types, answers revealed

1
MCQhard

A developer is implementing OAuth 2.0 for a mobile app (public client) that needs to access a user's data from a third-party API. To mitigate the authorization code interception attack, which OAuth 2.0 extension should be used?

A.Device code grant
B.Client credentials grant
C.Implicit grant
D.PKCE
AnswerD

Proof Key for Code Exchange (PKCE) enhances the Authorization Code Grant flow, making it secure for public clients like mobile applications that cannot securely store a client secret. It mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and a `code_challenge` derived from it. The `code_challenge` is sent with the initial authorization request, and the `code_verifier` is later presented when exchanging the authorization code for an access token, proving the client's identity without a shared secret.

Why this answer

PKCE (Proof Key for Code Exchange) is an extension to OAuth 2.0 designed to mitigate authorization code interception attacks, especially for public clients like mobile apps. It works by having the client generate a code verifier and its transformed code challenge, which are used to bind the authorization request to the token request. This prevents an attacker who intercepts the authorization code from exchanging it for tokens.

Exam trap

CISSP often tests the misconception that the implicit grant is secure for mobile apps, or that PKCE is only for confidential clients, when it is actually critical for public clients.

How to eliminate wrong answers

Option A is wrong because the device code grant is for devices with limited input capabilities, not for mitigating interception. Option B is wrong because the client credentials grant is for machine-to-machine communication without a user context. Option C is wrong because the implicit grant is deprecated and does not provide the same security as PKCE; it returns tokens directly in the URL, which can be intercepted.

2
MCQeasy

Which access control model assigns permissions based on a user's job function?

A.MAC
B.DAC
C.ABAC
D.RBAC
AnswerD

Role-Based Access Control (RBAC) assigns permissions to specific roles, and then users are assigned to one or more roles based on their job functions or responsibilities within an organization. This model simplifies administration by managing permissions at the role level rather than individually for each user, ensuring that users only have the access necessary for their duties. RBAC is widely adopted due to its balance of security, flexibility, and ease of management, directly addressing the question's premise.

Why this answer

Role-Based Access Control (RBAC) assigns permissions to roles, and users are assigned to roles based on their job function. This means a user's access is determined by their role (e.g., 'HR Manager', 'Financial Analyst'), not by individual object ownership or attributes. RBAC is the standard model for enforcing least privilege in enterprise environments.

Exam trap

CISSP often tests the confusion between RBAC and ABAC — candidates see 'job function' and think of attributes, but job function is the classic RBAC trigger; ABAC uses multiple attributes and policies, not just role.

How to eliminate wrong answers

Option A is wrong because MAC (Mandatory Access Control) assigns permissions based on security labels (e.g., Top Secret, Confidential) and clearance levels, not job function. Option B is wrong because DAC (Discretionary Access Control) lets the owner of a resource decide who gets access, which is not based on job function. Option C is wrong because ABAC (Attribute-Based Access Control) uses a combination of attributes (user, resource, environment) and policies, which is more granular than job-function roles.

3
MCQmedium

A security policy requires that a user cannot have both the ability to create purchase orders and approve invoices. This is an example of:

A.Separation of duties
B.Need-to-know
C.Least privilege
D.Job rotation
AnswerA

Separation of duties (SoD) is a critical preventative control designed to mitigate the risk of fraud, error, or misuse by ensuring that no single individual possesses all the necessary permissions or capabilities to complete a critical or sensitive transaction end-to-end. This policy directly addresses the requirement that a user cannot have both conflicting responsibilities, thereby preventing a single point of failure or malicious action. It mandates that distinct, high-risk tasks are divided among multiple people.

Why this answer

Separation of duties is a principle that prevents a single individual from having control over all aspects of a critical process. In this case, requiring that a user cannot both create purchase orders and approve invoices ensures that no single person can initiate and authorize a transaction, reducing the risk of fraud or error. This is a classic example of separation of duties.

Exam trap

CISSP often tests the confusion between separation of duties and least privilege, as both involve limiting access, but SoD specifically addresses conflicting responsibilities.

How to eliminate wrong answers

Option B is wrong because need-to-know restricts access to information based on job requirements, not the division of tasks. Option C is wrong because least privilege gives users only the minimum access necessary to perform their job, but does not necessarily prevent the same user from having both create and approve permissions if both are deemed necessary. Option D is wrong because job rotation involves moving employees through different roles to prevent fraud, but does not inherently prevent a user from having both permissions at the same time.

4
Multi-Selecthard

A security analyst is performing an access review. Which THREE of the following are best practices for user access recertification? (Choose three.)

Select 3 answers
A.Managers confirm that employees still need their current access
B.Remove all access and re-provision as needed
C.Perform recertification annually or more frequently
D.Review access against job roles and responsibilities
E.Automatically approve access if no response
AnswersA, C, D

Managers are uniquely positioned to confirm the ongoing business necessity of an employee's access privileges, as they possess direct insight into daily job functions and responsibilities. This crucial step ensures that access rights align with the principle of least privilege, preventing the accumulation of unnecessary permissions and reducing the overall attack surface within the organization. This verification is fundamental to maintaining a secure access posture.

Why this answer

Option A is correct because the core of user access recertification is having managers (or resource owners) explicitly attest that each user still requires their current entitlements; this human validation catches stale or excessive privileges that automated tools cannot infer. Option C is correct because recertification must occur on a defined, recurring schedule—at least annually, and more frequently for privileged, sensitive, or high-risk access—so that access does not drift out of policy over time. Option D is correct because reviews must compare each user's granted access against their current job role and responsibilities, ensuring the principle of least privilege and separation of duties are maintained.

Option B is not a best practice because removing all access and re-provisioning from scratch is disruptive, error-prone, and unnecessary when targeted review can revoke only inappropriate entitlements. Option E is not a best practice because auto-approving access when a reviewer does not respond defeats the purpose of recertification and allows unjustified access to persist; non-response should trigger escalation or revocation, not approval.

Exam trap

The trap is the 'no response = approve' option, which sounds convenient but violates least-privilege principles; CISSP candidates must recognize that silence should never be treated as consent in access reviews.

5
Multi-Selecteasy

Which TWO of the following are examples of Type 3 authentication factors? (Choose two.)

Select 2 answers
A.Password
B.Fingerprint
C.Smart card
D.One-time password token
E.Retina scan
AnswersB, E

A fingerprint scan is a classic example of Type 3 authentication, which relies on "something you are." This biometric factor captures unique physiological patterns from an individual's finger to verify identity, providing a high level of non-repudiation compared to knowledge or possession factors.

Why this answer

Type 3 authentication factors are "something you are" — biometric characteristics unique to an individual — so B (Fingerprint) is correct because a fingerprint is a physical biometric trait verified by matching minutiae patterns, and E (Retina scan) is correct because it analyzes the unique blood-vessel pattern of the retina, another physiological biometric. The remaining options are not Type 3: A (Password) is a Type 1 factor (something you know), while C (Smart card) and D (One-time password token) are Type 2 factors (something you have), since they rely on possession of a physical device or generated token rather than an inherent biological trait.

Exam trap

CISSP often tests whether candidates can correctly categorize authentication factors — the trap is confusing Type 2 (something you have, like a smart card or OTP token) with Type 3 (something you are, like a fingerprint).

6
Multi-Selectmedium

A security analyst is reviewing access controls for a financial application. Which TWO of the following are considered best practices for preventing fraud? (Select TWO.)

Select 2 answers
A.Password complexity
B.Single sign-on
C.Least privilege
D.Two-person control
E.Separation of duties
AnswersD, E

Two-person control, also known as the "two-man rule" or dual control, is a procedural security mechanism requiring the simultaneous involvement and agreement of two authorized individuals to perform a critical or sensitive action. This control prevents a single person from initiating or completing a high-risk transaction or operation, significantly mitigating the risk of fraud, error, or malicious intent by ensuring mutual oversight and accountability. It directly addresses the need for multiple people to complete a sensitive action.

Why this answer

Two-person control (D) is a best practice for preventing fraud because it requires two authorized individuals to perform a critical action, such as approving a high-value transaction or accessing a sensitive system. This ensures collusion is needed to commit fraud, as no single person can complete the action alone. In a financial application, this might involve dual approval for wire transfers over a threshold, directly mitigating insider threats.

Exam trap

The trap here is that candidates often confuse 'least privilege' (a preventive control for limiting access) with 'separation of duties' (a detective/preventive control for fraud), or they incorrectly think 'password complexity' or 'single sign-on' directly prevent fraud when they only address authentication security.

7
MCQmedium

In SAML 2.0, which component is responsible for authenticating the user and generating an assertion?

A.Identity Provider (IdP)
B.Service Provider (SP)
C.Certificate Authority (CA)
D.Relying Party (RP)
AnswerA

The Identity Provider (IdP) is the authoritative entity responsible for authenticating the user's identity within a SAML 2.0 federation. It verifies user credentials against its own identity store (e.g., an LDAP directory or database) and, upon successful authentication, generates a digitally signed SAML assertion containing the user's authentication status and relevant attributes. This assertion is then securely transmitted to the Service Provider, confirming the user's identity without sharing their actual credentials.

Why this answer

In SAML 2.0, the Identity Provider (IdP) is the entity that authenticates the user and issues the SAML assertion containing authentication and attribute statements. The Service Provider (SP) consumes that assertion to grant access. The IdP is the authoritative source of identity, so it is the component that generates the assertion.

Exam trap

CISSP often tests SAML role terminology, so the trap is confusing the Service Provider/Relying Party (consumer) with the Identity Provider (issuer), or selecting Certificate Authority because it sounds like the component that 'validates' assertions.

How to eliminate wrong answers

Option B is wrong because the Service Provider is the relying application that requests authentication and consumes the assertion; it does not authenticate the user or generate the assertion. Option C is wrong because a Certificate Authority issues X.509 certificates used to sign and validate SAML assertions, but it plays no role in authenticating users or generating assertions. Option D is wrong because Relying Party is essentially a synonym for Service Provider in federation terminology (and the term used in OIDC), so it is the consumer, not the issuer, of the assertion.

8
Multi-Selectmedium

Which TWO of the following are OAuth 2.0 grant types? (Choose two.)

Select 2 answers
A.SAML assertion
B.Client credentials
C.LDAP bind
D.Kerberos ticket
E.Authorization code
AnswersB, E

The Client Credentials grant type is specifically designed for machine-to-machine authentication, where a confidential client (e.g., a service, daemon, or another API) needs to access protected resources on behalf of itself, rather than a specific end-user. In this flow, the client authenticates directly with the authorization server using its own client ID and client secret, receiving an access token that grants it access to resources it is authorized for. This grant is ideal for server-to-server interactions or automated processes where no user interaction is present or required.

Why this answer

Option B (Client credentials) is correct because the client credentials grant is one of the standard OAuth 2.0 grant types defined in RFC 6749, used for machine-to-machine authentication where the client requests an access token using its own credentials without a resource owner. Option E (Authorization code) is correct because the authorization code grant is the core OAuth 2.0 flow defined in RFC 6749, where the client exchanges an authorization code obtained via the authorization endpoint for an access token at the token endpoint. The other options do not belong: SAML assertion (A) is an XML-based authentication/authorization standard used in SAML bearer assertions, not an OAuth 2.0 grant type; LDAP bind (C) is an authentication operation in the LDAP protocol, not an OAuth grant; and Kerberos ticket (D) is a ticket-based authentication mechanism in the Kerberos protocol, unrelated to OAuth 2.0 grant types.

Exam trap

CISSP often tests whether candidates can distinguish OAuth 2.0 grant types from other authentication protocols like SAML, LDAP, and Kerberos, so they pick protocol names that sound like grants but are not part of OAuth 2.0.

9
MCQhard

Which access control model bases decisions on attributes of the user, resource, and environment, and can use Boolean logic to define policies?

A.Role-Based Access Control (RBAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Mandatory Access Control (MAC)
AnswerC

Attribute-Based Access Control (ABAC) makes access decisions by evaluating a comprehensive set of attributes associated with the subject (e.g., user's department, clearance level), the object (e.g., resource sensitivity, file type), the action being requested (e.g., read, write), and the environmental context (e.g., time of day, network location). This highly dynamic and granular model uses policies that define rules based on these combined attributes, enabling context-aware authorization beyond static roles or identities.

Why this answer

ABAC (Attribute-Based Access Control) evaluates attributes of the subject (user), object (resource), and environment (context such as time, location, or threat level) to make access decisions. It supports Boolean logic (AND, OR, NOT) to combine these attributes into fine-grained policies, enabling dynamic and context-aware authorization. This contrasts with RBAC, which relies on roles, and MAC/DAC, which use labels or ownership, respectively.

Exam trap

CISSP often tests the confusion between RBAC and ABAC, where candidates mistakenly select RBAC because they overlook the requirement for environmental attributes and Boolean logic, which are defining features of ABAC.

How to eliminate wrong answers

Option A is wrong because RBAC bases decisions on roles assigned to users, not on a combination of user, resource, and environmental attributes, and it does not inherently use Boolean logic for policy definition. Option B is wrong because DAC bases decisions on the discretion of the resource owner (e.g., via ACLs), not on attributes of user, resource, and environment. Option D is wrong because MAC bases decisions on security labels (e.g., clearance and classification) and is non-discretionary, lacking the dynamic attribute-based and Boolean logic capabilities of ABAC.

10
MCQmedium

An organization wants to enable single sign-on (SSO) across multiple web applications using an XML-based protocol that supports browser redirect flows. Which technology is most appropriate?

A.Kerberos
B.OAuth 2.0
C.OpenID Connect (OIDC)
D.SAML 2.0
AnswerD

SAML 2.0 (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. It is specifically designed to facilitate browser-based single sign-on (SSO) for web applications across different security domains, allowing users to authenticate once and gain access to multiple services without re-entering credentials. Its robust support for federated identity management makes it a cornerstone for enterprise SSO solutions.

Why this answer

SAML 2.0 is an XML-based federation standard designed specifically for browser-based SSO via HTTP Redirect and POST bindings, where the IdP issues a signed XML assertion to the SP. It is the canonical choice when the requirement explicitly says 'XML-based protocol' and 'browser redirect flows.'

Exam trap

CISSP often tests SAML vs OIDC by emphasizing 'XML-based' — candidates who default to OIDC because it's 'modern' miss that the question explicitly requires XML.

How to eliminate wrong answers

Option A is wrong because Kerberos is a ticket-based authentication protocol for domain environments (typically Windows/AD) and is not XML-based nor designed for cross-domain web SSO via browser redirects. Option B is wrong because OAuth 2.0 is an authorization framework (JSON/REST, not XML) and does not itself authenticate users or provide SSO identity assertions. Option C is wrong because OpenID Connect is built on OAuth 2.0 and uses JSON/JWT tokens, not XML, so it fails the 'XML-based' requirement even though it does support browser redirect flows.

11
MCQeasy

Which authentication factor type is a smart card?

A.Somewhere you are
B.Type 2 (something you have)
C.Type 3 (something you are)
D.Type 1 (something you know)
AnswerB

A smart card is a quintessential example of a "something you have" authentication factor because it is a tangible, physical item that the user must possess and present for authentication. This factor relies on the physical control of an object, such as a cryptographic token, USB key, or in this case, a smart card. The card securely stores cryptographic keys or digital certificates, which are accessed only when the card is physically inserted into a compatible reader, thereby proving possession.

Why this answer

A smart card is a Type 2 authentication factor because it falls under the 'something you have' category. The card itself is a physical device that stores a digital certificate or cryptographic key, which the user must possess to authenticate. Unlike knowledge-based or biometric factors, possession of the smart card is the core authentication mechanism, often combined with a PIN (Type 1) for two-factor authentication.

Exam trap

The trap here is that candidates confuse 'something you have' (Type 2) with 'something you are' (Type 3) because smart cards are often used with biometric readers, but the card itself is a possession factor, not a biometric.

How to eliminate wrong answers

Option A is wrong because 'Somewhere you are' is not a standard authentication factor type in the CISSP framework; it is a location-based attribute, not a factor category. Option C is wrong because Type 3 (something you are) refers to biometric characteristics such as fingerprints or iris scans, not a physical token like a smart card. Option D is wrong because Type 1 (something you know) includes passwords, PINs, or passphrases, whereas a smart card is a tangible object, not knowledge.

12
MCQmedium

OpenID Connect (OIDC) extends OAuth 2.0 primarily by adding which capability?

A.Client credential management
B.Authorization delegation
C.Token introspection
D.User authentication
AnswerD

OpenID Connect (OIDC) primarily extends OAuth 2.0 by adding a standardized layer for user authentication. While OAuth 2.0 focuses solely on authorization, allowing a client to obtain delegated access to protected resources, OIDC introduces the concept of an ID Token. This ID Token, a JSON Web Token (JWT), provides verifiable claims about the authenticated user, enabling the client application to confirm the user's identity and retrieve basic profile information.

Why this answer

OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0 that primarily adds user authentication. While OAuth 2.0 provides authorization delegation (access tokens for resources), OIDC introduces an ID token (a JSON Web Token, JWT) that contains claims about the authenticated user, enabling the client to verify the user's identity. This is defined in the OIDC specification (OpenID Foundation) and is the key differentiator from plain OAuth 2.0.

Exam trap

The trap here is that candidates often confuse OAuth 2.0's authorization delegation (access tokens for resources) with OIDC's authentication (ID tokens for user identity), leading them to incorrectly select 'Authorization delegation' as the primary addition.

How to eliminate wrong answers

Option A is wrong because client credential management is a feature of OAuth 2.0 itself (e.g., client_id, client_secret, client credentials grant type), not something OIDC adds. Option B is wrong because authorization delegation is the core purpose of OAuth 2.0, not an extension provided by OIDC; OIDC adds authentication on top of that delegation. Option C is wrong because token introspection is an OAuth 2.0 extension (RFC 7662) for validating token status, not a feature introduced by OIDC; OIDC uses the UserInfo endpoint for identity claims.

13
MCQhard

A multinational bank must enforce least privilege across 4,000 roles that change frequently as employees move between trading, compliance, and IT functions. Auditors found that access reviews are performed manually and that role definitions drift from actual job duties. The identity team proposes a role mining and management program. Which approach best aligns with identity and access management governance objectives while reducing role explosion?

A.Create a unique role for every employee based on their current entitlements and assign it during onboarding.
B.Eliminate all roles and assign entitlements directly to each user through workflow-based access requests.
C.Perform bottom-up role mining to derive candidate roles from existing entitlement data, then normalize and approve them through a role governance board.
D.Adopt a top-down role engineering approach that defines roles solely from the organizational chart and job descriptions.
AnswerC

Bottom-up role mining analyzes actual entitlement assignments to identify common access patterns and proposes candidate roles, which are then refined and approved by business owners. This reduces role sprawl, aligns roles with real job functions, and creates a governed, reviewable role catalog, directly addressing the drift and manual review problems.

Why this answer

Bottom-up role mining derives roles from observed entitlement patterns, which exposes drift between documented and actual access and produces a smaller, business-relevant role set. Normalizing and approving candidates through a governance board keeps roles controlled and auditable, reducing role explosion while supporting least privilege and repeatable access reviews across the bank's diverse functions.

Exam trap

The trap here is treating role mining as purely technical and skipping governance approval, or assuming that eliminating roles removes the need for access reviews.

14
MCQmedium

In an OAuth 2.0 authorization code flow with PKCE, what is the primary purpose of the code verifier and code challenge?

A.To encrypt the authorization code
B.To authenticate the end user
C.To ensure the client that requested the code is the same one redeeming it
D.To generate the ID token
AnswerC

This statement accurately describes the core purpose of PKCE. By requiring the client to generate a `code_verifier` and send a transformed `code_challenge` at the beginning of the flow, then present the original `code_verifier` when redeeming the authorization code, PKCE ensures that only the client that initiated the request can successfully exchange the code for tokens. This mechanism effectively prevents authorization code interception attacks, where a malicious application might steal the code and impersonate the legitimate client.

Why this answer

In OAuth 2.0 authorization code flow with PKCE, the code verifier and code challenge are used to prove that the client redeeming the authorization code is the same client that initiated the authorization request. The client generates a random code verifier, hashes it to create the code challenge, sends the challenge with the authorization request, and later sends the verifier with the token request — the authorization server verifies they match. This prevents authorization code interception attacks, especially for public clients.

Exam trap

The trap is assuming PKCE encrypts the authorization code or authenticates the user; candidates who don't understand that PKCE binds the code to the requesting client pick options about encryption or user authentication.

How to eliminate wrong answers

Option A is wrong because PKCE does not encrypt the authorization code; the code is still transmitted as-is, and PKCE adds a proof-of-possession check, not encryption. Option B is wrong because PKCE does not authenticate the end user — user authentication is handled by the authorization server (e.g., via login credentials or federation), and PKCE is about client verification. Option D is wrong because the ID token is generated by the OpenID Connect provider as part of authentication, not by PKCE; PKCE does not generate or influence the ID token.

15
MCQmedium

A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implemented?

A.Biometric authentication
B.Step-up authentication
C.Single-factor authentication
D.Multi-factor authentication
AnswerD

Multi-factor authentication (MFA) is the correct choice because it precisely describes an authentication system that requires a user to present two or more independent authentication factors from different categories to verify their identity. By combining distinct types, such as 'something you know' (e.g., a password) and 'something you have' (e.g., a token or smart card), MFA significantly enhances security. This approach ensures that even if one factor is compromised, unauthorized access is prevented due to the requirement for a second, different factor.

Why this answer

Multi-factor authentication (MFA) requires two or more different categories of authentication factors: something you know (password), something you have (hardware token), and something you are (biometric). Here, the password is a knowledge factor and the one-time code from a hardware token is a possession factor, satisfying the definition of MFA. Because the factors come from distinct categories, this is not single-factor or step-up authentication.

Exam trap

CISSP often tests the distinction between authentication factors and the misconception that any two authentication steps constitute MFA, when they must be from different categories.

How to eliminate wrong answers

Option A is wrong because biometric authentication relies on something you are (e.g., fingerprint, retina), and no biometric factor is mentioned in the scenario. Option B is wrong because step-up authentication refers to increasing the authentication assurance level when accessing more sensitive resources, not the initial login method described. Option C is wrong because single-factor authentication would require only one factor (e.g., just a password), but the scenario uses two distinct factors.

16
MCQhard

During a Kerberos authentication process, the client receives a Ticket Granting Ticket (TGT) from the Authentication Server (AS). Later, the client presents the TGT to the Ticket Granting Server (TGS) to request a service ticket. Which of the following best describes the purpose of the TGT?

A.It verifies the client's IP address to prevent replay attacks.
B.It allows the client to request additional service tickets without re-authentication.
C.It encrypts the session key between the client and the target service.
D.It authenticates the user to the target service directly.
AnswerB

The Ticket Granting Ticket (TGT) is a crucial component that facilitates single sign-on within a Kerberos realm. Once a client successfully authenticates to the Authentication Service (AS) and receives a TGT, this ticket serves as proof of their identity to the Ticket Granting Service (TGS). This allows the client to subsequently request service tickets for various network services without needing to re-enter their password or re-authenticate to the KDC for each new service.

Why this answer

The TGT is correct because it is issued once by the Authentication Server after the client proves its identity (typically via password-derived pre-authentication), and it is then presented to the TGS to obtain service tickets for specific resources — enabling single sign-on without re-entering credentials. The TGT is encrypted with the krbtgt account's secret key, so only the KDC can decrypt and validate it, and it carries the client's identity and a session key for securing subsequent TGS exchanges. This design is what makes Kerberos efficient: authenticate once, then request many service tickets.

Exam trap

CISSP often tests whether candidates conflate the TGT with the service ticket, so the trap is choosing an answer that describes service-ticket behavior (direct authentication to a resource) as the TGT's purpose.

How to eliminate wrong answers

Option A is wrong because Kerberos does not rely on IP address verification for replay protection; it uses timestamps and nonces within authenticators, and IP binding is not a core Kerberos mechanism (though some implementations add it as a hardening measure). Option C is wrong because the session key between client and target service is generated by the TGS and delivered inside the service ticket, not by the TGT itself — the TGT's session key only protects client-to-KDC communication. Option D is wrong because the TGT does not authenticate the user to the target service directly; the client must first exchange the TGT for a service ticket, and it is that service ticket (encrypted with the service's long-term key) that authenticates the user to the resource.

17
MCQhard

An organization discovers that a former employee's account is still active and has been used to access sensitive data. This is an example of which type of risk?

A.Orphaned account
B.Privilege escalation
C.Social engineering
D.Insider threat
AnswerA

An orphaned account is an active user account that no longer has an associated legitimate user, typically because the employee has left the organization but their account was not properly deprovisioned or disabled. This oversight creates a significant security vulnerability, as the account could be exploited by an attacker or the former employee themselves to gain unauthorized access to systems and data. The discovery of a former employee's active account directly indicates a failure in the organization's identity and access management offboarding process.

Why this answer

The scenario describes an account that should have been deprovisioned when the employee left but remained active — that is precisely an orphaned account. The fact that it was used to access sensitive data highlights the risk orphaned accounts create, but the root condition being tested is the orphaned account itself. Orphaned accounts are a well-known access control weakness in identity lifecycle management.

Exam trap

The trap is choosing 'insider threat' because a former employee accessed data; the exam distinguishes the underlying access control defect (orphaned account) from the resulting threat category.

How to eliminate wrong answers

Option B is wrong because privilege escalation involves an actor gaining elevated rights, whereas here the issue is an unmanaged account retaining its existing access. Option C is wrong because social engineering involves manipulating people into divulging information or access, which is not described. Option D is wrong because insider threat implies a current insider misusing access; a former employee's leftover account is more precisely classified as an orphaned account, even though it can enable insider-style abuse.

18
Multi-Selectmedium

A security administrator is reviewing potential risks associated with orphaned accounts. Which TWO of the following are risks of orphaned accounts?

Select 2 answers
A.Compliance with password policies is weakened
B.Performance degradation of authentication servers
C.Increased logging overhead
D.Attackers can use orphaned accounts to gain unauthorized access
E.Former employees can still access systems
AnswersD, E

Attackers actively seek out orphaned accounts because they often represent overlooked security gaps. These accounts may retain elevated privileges, possess weak or default passwords that were never updated, or simply go unnoticed in routine security audits, making them prime targets for credential stuffing, brute-force attacks, or lateral movement once initial network access is achieved. Exploiting such accounts provides a persistent backdoor for unauthorized access and privilege escalation.

Why this answer

Option D is correct because orphaned accounts remain valid credentials that are no longer tied to an active owner, so an attacker who compromises or guesses those credentials can authenticate and move laterally without triggering account-owner scrutiny. Option E is correct because orphaned accounts often belong to former employees, contractors, or vendors whose access was never revoked, allowing those individuals to retain system access after their relationship with the organization ends. These two risks are the core security concerns of orphaned accounts: unauthorized access by external attackers and lingering access by terminated insiders.

Option A is not the primary risk here because password-policy compliance is a control weakness rather than a direct orphaned-account risk, and orphaned accounts may still technically meet password complexity or rotation rules. Option B is incorrect because authentication-server performance is a capacity/scalability issue, not a consequence of accounts lacking an owner. Option C is incorrect because increased logging overhead is an operational side effect, not a distinct risk of orphaned accounts.

Exam trap

CISSP often tests the distinction between direct security risks (unauthorized access, insider threat) and indirect operational issues (performance, logging), so candidates may incorrectly select operational impacts as risks of orphaned accounts.

19
MCQmedium

A healthcare organization uses a federated identity provider (IdP) to authenticate clinicians into a third-party electronic health record (EHR) application acting as a SAML 2.0 Service Provider (SP). The security team wants to reduce the risk that a stolen IdP session cookie could be replayed against the EHR. Which SAML 2.0 control should the team implement to bind the assertion to the authenticated browser session and limit replay?

A.Enable SAML 2.0 Single Logout (SLO) between the IdP and the EHR Service Provider.
B.Require the IdP to include a Holder-of-Key (HoK) subject confirmation in the assertion and have the SP verify possession of the corresponding key.
C.Configure the IdP to issue short-lived assertions and require the SP to validate the NotOnOrAfter condition against its own clock.
D.Use SAML 2.0 Enhanced Client or Proxy (ECP) profile so the EHR can request authentication directly from the IdP.
AnswerB

Holder-of-Key subject confirmation binds the assertion to a key the requester must prove possession of, so a stolen session cookie alone cannot satisfy the SP. This directly addresses replay of a captured assertion or cookie, which is exactly the risk the security team wants to reduce for clinician access to the EHR.

Why this answer

Binding a SAML assertion to a key the requester must prove possession of prevents an attacker who only has a stolen cookie from being accepted by the Service Provider, because the attacker cannot demonstrate possession of the associated private key. Short-lived assertions, Single Logout, and the ECP profile change timing or transport but leave the assertion bearer-based and replayable within its validity window.

Exam trap

The trap here is assuming that shortening assertion lifetime or enabling Single Logout prevents cookie replay, when neither binds the assertion to the requester's session.

20
MCQeasy

Which of the following is an example of a Type 1 authentication factor?

A.OTP token
B.Fingerprint
C.Password
D.Smart card
AnswerC

A password serves as a classic example of a Type 1 authentication factor, representing "something you know." This form of authentication relies on a secret piece of information, such as a string of characters, that only the legitimate user is supposed to possess and recall. Users must cognitively remember and accurately input this credential to prove their identity, making it a foundational element in most access control systems. Its security is directly dependent on its complexity and the user's ability to keep it confidential.

Why this answer

A Type 1 authentication factor is something you know, such as a password, PIN, or passphrase. The password is knowledge held in the user's memory, making it the classic example of a Type 1 factor. The other options represent possession (something you have) or inherence (something you are).

Exam trap

CISSP often tests the distinction between authentication factor types, and candidates frequently misclassify smart cards or OTP tokens as Type 1 because they involve user interaction, forgetting that possession is the defining characteristic.

How to eliminate wrong answers

Option A is wrong because an OTP token is a possession factor (Type 2) — the user has a physical or virtual device that generates one-time codes. Option B is wrong because a fingerprint is a biometric inherence factor (Type 3) — it is a physical characteristic of the user. Option D is wrong because a smart card is a possession factor (Type 2) — the user must have the physical card, even if it also stores a certificate.

21
MCQhard

An attacker who has compromised the Kerberos Key Distribution Center (KDC) could forge a Ticket Granting Ticket (TGT) to impersonate any user. This type of attack is known as:

A.Golden ticket attack
B.Silver ticket attack
C.Pass-the-ticket attack
D.Kerberos poisoning attack
AnswerA

A golden ticket attack leverages a compromised Kerberos Key Distribution Center (KDC) account's NTLM hash (specifically, the krbtgt account) to forge a valid Ticket Granting Ticket (TGT). This forged TGT grants the attacker unlimited, domain-wide administrative access to all resources within the Active Directory environment. The attacker can impersonate any user, including non-existent ones, and request service tickets for any service without further authentication from the legitimate KDC.

Why this answer

A Golden Ticket attack involves compromising the Kerberos Key Distribution Center (KDC), specifically the KRBTGT account's password hash. With this hash, an attacker can forge a legitimate Ticket Granting Ticket (TGT) that grants access to any service or resource in the domain, effectively impersonating any user. This is possible because the KRBTGT account is used to sign all TGTs, and its compromise allows the attacker to mint arbitrary TGTs.

The attack is called 'Golden' because it grants unlimited access, akin to having a master key to the domain.

Exam trap

CISSP often tests the distinction between Golden Ticket and Silver Ticket attacks, where candidates may confuse the scope of compromise (KDC vs. service account) and the type of ticket forged (TGT vs. TGS).

How to eliminate wrong answers

Option B is wrong because a Silver ticket attack forges a Service Ticket (TGS) using the compromised service account's password hash, not the KDC's KRBTGT hash, and it only grants access to that specific service, not domain-wide impersonation. Option C is wrong because Pass-the-ticket involves stealing a valid existing Kerberos ticket (TGT or TGS) from memory and reusing it, not forging a new one from scratch. Option D is wrong because 'Kerberos poisoning' is not a standard term; it may refer to attacks like Kerberoasting or AS-REP roasting, which involve requesting and cracking tickets, not forging TGTs via KDC compromise.

22
MCQhard

In OAuth 2.0, which grant type is recommended for a native mobile application that cannot securely store a client secret, and uses PKCE?

A.Client Credentials grant
B.Implicit grant
C.Device Code grant
D.Authorization Code grant with PKCE
AnswerD

The Authorization Code grant with Proof Key for Code Exchange (PKCE) is the recommended and most secure flow for public clients like native mobile applications. PKCE mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and send its hash (`code_challenge`) during the initial authorization request. The same `code_verifier` must then be presented when exchanging the authorization code for an access token, ensuring only the legitimate client that initiated the request can complete the exchange, even if the code is intercepted.

Why this answer

The Authorization Code grant with PKCE (Proof Key for Code Exchange, RFC 7636) is the OAuth 2.0 best practice for public clients like native mobile apps that cannot keep a client secret. PKCE replaces the static client secret with a dynamically generated code_verifier/code_challenge pair, preventing authorization code interception attacks.

Exam trap

CISSP often tests the misconception that the Implicit grant is still acceptable for mobile/SPA clients — candidates must know it is deprecated in favor of Authorization Code + PKCE.

How to eliminate wrong answers

Option A is wrong because the Client Credentials grant is for machine-to-machine (confidential) clients with no user context and requires a client secret — inappropriate for a mobile app acting on behalf of a user. Option B is wrong because the Implicit grant returns tokens directly in the URL fragment, is deprecated in OAuth 2.1, and is vulnerable to token leakage; it does not use PKCE. Option C is wrong because the Device Code grant is designed for input-constrained devices (smart TVs, CLI) where the user authorizes on a separate device, not for a native mobile app that has a browser.

23
MCQmedium

In a Privileged Access Management (PAM) solution, which feature provides temporary elevation of privileges for specific tasks, reducing the risk of standing privileges?

A.Password vaulting
B.Just-in-time (JIT) access
C.Break-glass account
D.Session recording
AnswerB

Just-in-time (JIT) access is a critical security feature within a PAM solution that grants elevated privileges only when needed and for a strictly limited duration. This approach minimizes the attack surface by eliminating standing privileges, ensuring that users possess administrative rights solely for the specific task and time required. Once the task is completed or the predefined time expires, the privileges are automatically revoked, significantly reducing the window of opportunity for credential misuse or compromise.

Why this answer

Just-in-time (JIT) access in a PAM solution provides temporary, on-demand elevation of privileges for specific tasks, eliminating standing privileges that attackers can exploit. It typically involves approval workflows, time-bound access, and automatic revocation. This reduces the attack surface and limits lateral movement.

Exam trap

CISSP often tests the difference between password vaulting and JIT access; candidates may confuse vaulting (credential storage) with JIT (temporary elevation), but the question specifically asks for temporary elevation.

How to eliminate wrong answers

Option A is wrong because password vaulting stores and manages privileged credentials but does not inherently provide temporary elevation; it can be part of a PAM solution but does not by itself reduce standing privileges. Option C is wrong because a break-glass account is an emergency account used when normal access is unavailable; it is not for routine temporary elevation and often has standing privileges. Option D is wrong because session recording monitors and records privileged sessions for auditing but does not grant or elevate privileges; it is a detective control, not a preventive one.

24
Multi-Selectmedium

Which TWO of the following are characteristics of a Privileged Access Management (PAM) solution? (Choose two.)

Select 2 answers
A.Self-service password reset
B.Session recording
C.Single sign-on for all users
D.Password vaulting
E.OpenID Connect authentication
AnswersB, D

Session recording is a critical characteristic of Privileged Access Management (PAM) systems, capturing video-like records of all activities performed by privileged users during their elevated sessions. This capability provides an immutable audit trail, enabling forensic analysis, compliance reporting, and real-time monitoring of sensitive operations. By documenting every command and action, organizations can ensure accountability and detect unauthorized or suspicious behavior associated with high-risk accounts.

Why this answer

Option B (Session recording) is correct because PAM solutions commonly record and audit privileged sessions (e.g., via SSH/RDP proxies) to provide accountability and forensic evidence for administrative activity. Option D (Password vaulting) is correct because PAM centrally stores, checks out, and rotates privileged credentials (such as root, admin, and service accounts) in an encrypted vault, which is a core PAM capability. Option A (Self-service password reset) is typically an identity management/helpdesk feature for standard users, not a defining PAM characteristic.

Option C (Single sign-on for all users) is an access-management/SSO capability rather than PAM-specific, since PAM focuses on privileged accounts and sessions. Option E (OpenID Connect authentication) is an authentication protocol/federation mechanism, not a characteristic that defines a PAM solution.

Exam trap

CISSP often tests the confusion between PAM and IAM features — candidates may select SSO or self-service reset, which are IAM capabilities, rather than PAM-specific functions like session recording and vaulting.

25
Multi-Selecthard

An organization is implementing a Privileged Access Management (PAM) solution. Which THREE of the following are common features of PAM? (Select THREE.)

Select 3 answers
A.Single sign-on
B.Password vaulting
C.Session recording
D.Just-in-time access
E.Role-based access control
AnswersB, C, D

Password vaulting is a fundamental PAM capability that centralizes the secure storage of privileged account credentials, such as administrator passwords and SSH keys, in an encrypted and isolated repository. It enforces strong password policies, automates credential rotation at defined intervals, and manages the secure retrieval and injection of these credentials into target systems, eliminating direct user knowledge of the actual passwords. This significantly reduces the risk of credential theft and misuse.

Why this answer

Password vaulting (B) is a core PAM capability because it stores privileged credentials in an encrypted repository and checks them out to authorized users, removing the need to expose or memorize administrative passwords. Session recording (C) is also a standard PAM feature, as it captures privileged sessions (often via RDP, SSH, or database proxies) for auditing, forensics, and compliance evidence. Just-in-time access (D) is a hallmark of modern PAM because it grants elevated privileges only for a limited time and revokes them automatically, reducing standing administrative rights and the attack surface.

Single sign-on (A) and role-based access control (E) are identity and access management concepts that may integrate with PAM, but they are not defining PAM features in the same way as vaulting, session recording, and just-in-time elevation.

Exam trap

CISSP often tests whether candidates can distinguish PAM-specific features (vaulting, session recording, JIT) from general IAM features (SSO, RBAC) that are commonly present but not unique to PAM.

26
Multi-Selectmedium

Which THREE of the following are components of a Privileged Access Management (PAM) solution?

Select 3 answers
A.User self-service password reset
B.Single sign-on for web applications
C.Session recording
D.Just-in-time access
E.Password vaulting
AnswersC, D, E

Session recording is a critical component of Privileged Access Management (PAM) that captures and archives all activities performed during a privileged session. This includes keystrokes, mouse movements, and screen content, providing an immutable audit trail. Such recordings are invaluable for forensic analysis, compliance auditing, and identifying unauthorized or suspicious actions by privileged users, enhancing accountability and security posture.

Why this answer

Session recording (C) is a core PAM component because it captures and audits privileged sessions (e.g., SSH, RDP) for accountability and forensic review. Just-in-time access (D) is a PAM capability that grants elevated privileges only when needed and for a limited time, reducing standing access. Password vaulting (E) is central to PAM, as it securely stores, rotates, and checks out privileged credentials.

User self-service password reset (A) and single sign-on for web applications (B) are identity and access management (IAM) features, not PAM-specific components.

Exam trap

The trap is that SSO and self-service password reset sound like 'access management' and get lumped in with PAM — remember PAM is specifically about privileged accounts, vaulting, JIT elevation, and session auditing.

27
MCQeasy

Which of the following is an example of a Type 2 authentication factor?

A.Smart card
B.PIN
C.Password
D.Fingerprint
AnswerA

A smart card represents 'something you have' (Type 2) because it is a physical token that must be possessed by the user to grant access. These cards typically contain an embedded microchip capable of performing cryptographic operations, such as storing digital certificates or generating one-time passwords. Its security relies on the physical control of the device, making it a robust authentication factor, often combined with a PIN for multi-factor authentication.

Why this answer

A smart card is a Type 2 authentication factor because it falls under the category of 'something you have.' Type 2 factors are possession-based, meaning the user must physically possess the token to authenticate. Smart cards store cryptographic keys or certificates and require a card reader to present the credential, making them a classic example of a possession factor.

Exam trap

The trap here is that candidates often confuse a smart card with a PIN or password because both are used together in practice, but the question specifically asks for the factor type of the smart card itself, not the combined authentication method.

How to eliminate wrong answers

Option B is wrong because a PIN (Personal Identification Number) is a Type 1 factor ('something you know'), not a Type 2 factor; it relies on knowledge rather than possession. Option C is wrong because a password is also a Type 1 factor, based on secret knowledge, not on a physical object. Option D is wrong because a fingerprint is a Type 3 factor ('something you are'), using biometric characteristics, not a possession-based factor.

28
MCQmedium

A security architect is designing an authentication system for a healthcare application that requires strong security. The system will use a password and a one-time passcode sent via SMS. How many authentication factor types are being used?

A.Three
B.Four
C.One
D.Two
AnswerD

This option is correct because the authentication system leverages two distinct types of factors to verify a user's identity. The password serves as the 'something you know' factor, requiring the user to recall a secret piece of information. The SMS One-Time Password (OTP), delivered to a registered mobile device, functions as the 'something you have' factor, relying on the user's possession of that specific device. This combination of two different factor categories precisely defines two-factor authentication (2FA).

Why this answer

Password is Type 1 (something you know), SMS OTP is Type 2 (something you have, as the phone is possessed). Only two factor types are used.

29
MCQhard

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Attribute-Based Access Control (ABAC)
AnswerA

DAC binds permissions to resource owners, who grant or revoke access at their discretion. This directly satisfies the stem's requirement that the owner determines both who may access the resource and which permissions they hold, unlike mandatory or role-based models where policy is centrally imposed.

Why this answer

Discretionary Access Control (DAC) allows the resource owner to control access at their discretion.

30
MCQmedium

In Kerberos authentication, what is the purpose of the Ticket Granting Ticket (TGT)?

A.To prove the user's identity to the Ticket Granting Service (TGS)
B.To store the user's password hash
C.To encrypt all communication between client and server
D.To authenticate the user to the resource server directly
AnswerA

The Ticket Granting Ticket (TGT) serves as a crucial credential, issued by the Authentication Server (AS), that the client presents to the Ticket Granting Service (TGS). It contains the user's identity and a session key, encrypted with the TGS's secret key, proving the user has been successfully authenticated by the AS. This allows the TGS to trust the client's request for service tickets without requiring re-authentication to the AS for each new service.

Why this answer

The TGT is issued by the Authentication Service (AS) after initial authentication and is used to prove the user's identity to the Ticket Granting Service (TGS) when requesting service tickets. It is encrypted with the TGS's secret key and contains the user's identity and session key.

Exam trap

CISSP often tests the confusion between TGT and service ticket; candidates may think the TGT directly authenticates to a resource server, but it's only used to obtain service tickets from the TGS.

How to eliminate wrong answers

Option B is wrong because the TGT does not store the user's password hash; it contains a session key and identity information. Option C is wrong because the TGT is not used to encrypt all communication; it is a ticket used for authentication, while session keys encrypt specific communications. Option D is wrong because the TGT is not used to authenticate directly to a resource server; the user must first obtain a service ticket from the TGS using the TGT.

31
MCQmedium

An LDAP distinguished name (DN) includes the attribute 'CN=John Doe,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

A.Country Name
B.Common Name
C.Certificate Name
D.Container Name
AnswerB

'CN' stands for Common Name, which is a fundamental attribute type used in LDAP Distinguished Names (DNs) to identify the most specific or common name of an entry within its immediate parent container. This attribute is widely employed for various object classes, such as users (e.g., "cn=John Doe"), groups, servers, or other resources, providing a human-readable identifier for the directory object. It forms a crucial part of the Relative Distinguished Name (RDN) for many entries.

Why this answer

In an LDAP distinguished name, CN stands for Common Name, which identifies the object (e.g., a user or group) by its common name attribute. In 'CN=John Doe,OU=Sales,DC=company,DC=com', CN=John Doe is the leaf RDN identifying the user. This is standard LDAP/X.500 naming.

Exam trap

CISSP often tests LDAP attribute abbreviations, so the trap is confusing CN (Common Name) with C (Country Name) or assuming CN relates to certificates rather than the directory attribute.

How to eliminate wrong answers

Option A is wrong because Country Name is represented by the C attribute (e.g., C=US), not CN. Option C is wrong because Certificate Name is not an LDAP attribute; certificates use CN in the subject field but the LDAP attribute itself is Common Name. Option D is wrong because Container Name is not an LDAP attribute; containers in AD are objects but the attribute is not CN in this sense.

32
Multi-Selecthard

Which TWO of the following are differences between OAuth 2.0 and OpenID Connect (OIDC)?

Select 2 answers
A.OAuth 2.0 supports device code grant, OIDC does not
B.OAuth 2.0 is for authorization, while OIDC is for authentication
C.OIDC is XML-based, while OAuth 2.0 is JSON-based
D.OIDC uses JSON Web Tokens (JWT) for ID tokens, while OAuth 2.0 does not define a token format
E.OAuth 2.0 requires a client secret, OIDC does not
AnswersB, D

This statement is correct and highlights a fundamental distinction. OAuth 2.0 is an authorization framework, primarily concerned with granting delegated access to protected resources without sharing user credentials. Conversely, OpenID Connect (OIDC) is an authentication protocol built on OAuth 2.0, specifically designed to verify the identity of an end-user and obtain basic profile information, issuing an ID Token for this purpose.

Why this answer

OAuth 2.0 is fundamentally an authorization framework (RFC 6749) that grants delegated access to resources, while OpenID Connect (OIDC) is an authentication layer built on top of OAuth 2.0 (specified in OpenID Connect Core 1.0) that verifies the end-user's identity. OIDC extends OAuth 2.0 by adding an ID token (a JWT) that contains claims about the authenticated user, whereas OAuth 2.0 alone does not provide identity information.

Exam trap

The CISSP exam often tests the misconception that OAuth 2.0 is for authentication and OIDC is for authorization, or that they are interchangeable, when in fact OAuth 2.0 is strictly authorization and OIDC is authentication built on top of it.

33
MCQmedium

An organization implements Single Sign-On (SSO) using SAML 2.0. A user attempts to access a cloud application (Service Provider) but is not authenticated. The Service Provider redirects the user to the Identity Provider (IdP) for authentication. Which type of SAML flow is this?

A.AuthN-initiated SSO
B.SP-initiated SSO
C.Assertion-initiated SSO
D.IdP-initiated SSO
AnswerB

SP-initiated SSO occurs when a user attempts to access a protected resource directly from a Service Provider (SP). The SP detects the unauthenticated request, generates a SAML authentication request, and redirects the user's browser to the Identity Provider (IdP) along with this request. After the IdP authenticates the user, it creates a SAML assertion and redirects the user's browser back to the SP, allowing the user to access the requested resource without re-authenticating directly to the SP.

Why this answer

In SAML 2.0, SP-initiated SSO occurs when the user first attempts to access a protected resource at the Service Provider (SP). The SP, finding no valid session, generates a SAML AuthnRequest and redirects the user to the Identity Provider (IdP) for authentication. This matches the scenario exactly: the user goes to the cloud application (SP) first, is redirected to the IdP, and then authentication proceeds.

Exam trap

CISSP often tests the distinction between SP-initiated and IdP-initiated SSO by describing the starting point of the user's access attempt; candidates frequently confuse the direction of the initial request and incorrectly choose IdP-initiated when the user actually starts at the application.

How to eliminate wrong answers

Option A is wrong because 'AuthN-initiated SSO' is not a standard SAML flow term; authentication is always initiated by either the SP or the IdP, and the exam expects recognition of the two canonical flows. Option C is wrong because 'Assertion-initiated SSO' is not a recognized SAML flow; assertions are produced by the IdP after authentication, not used to initiate the flow. Option D is wrong because IdP-initiated SSO begins at the IdP (e.g., user clicks an app in the IdP portal), and the IdP sends an unsolicited assertion to the SP without the SP first issuing an AuthnRequest.

34
MCQhard

An organization wants to implement single sign-on across multiple web applications using an XML-based protocol that supports identity provider (IdP) and service provider (SP) initiated flows. Which technology should they choose?

A.OpenID Connect
B.OAuth 2.0
C.SAML 2.0
D.Kerberos
AnswerC

SAML 2.0 (Security Assertion Markup Language) is an XML-based standard specifically designed for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It is widely adopted for enterprise single sign-on (SSO) scenarios, enabling users to authenticate once with an IdP and gain seamless access to multiple SPs without re-entering credentials. Its robust support for both IdP-initiated and SP-initiated flows makes it a strong choice for cross-domain SSO implementations.

Why this answer

SAML 2.0 is the XML-based federation standard that defines both IdP-initiated and SP-initiated SSO flows using assertions, AuthnRequests, and Response messages. It is the classic choice for browser-based SSO across multiple web applications where the identity provider and service provider exchange XML over HTTP POST or redirect bindings. OpenID Connect and OAuth 2.0 are JSON/REST-based, and Kerberos is a ticket-based network authentication protocol, not a web SSO federation standard.

Exam trap

CISSP often tests the SAML vs OIDC vs OAuth confusion — candidates must remember SAML is XML-based federation with IdP/SP roles, OIDC is JSON/JWT-based authentication, and OAuth 2.0 is authorization only.

How to eliminate wrong answers

Option A is wrong because OpenID Connect uses JSON Web Tokens (JWT) and REST endpoints, not XML, and is a newer OAuth 2.0-based layer rather than the XML protocol described. Option B is wrong because OAuth 2.0 is an authorization framework for delegated access, not an authentication/SSO protocol, and it is JSON-based. Option D is wrong because Kerberos is a symmetric-key ticket protocol used inside a realm (e.g., Active Directory), not an XML federation protocol for cross-domain web SSO.

35
MCQeasy

Which protocol is specifically designed for authorization and not authentication, often using grant types like authorization code and client credentials?

A.SAML 2.0
B.OpenID Connect
C.Kerberos
D.OAuth 2.0
AnswerD

OAuth 2.0 is an authorization framework specifically designed to enable a third-party application to obtain limited access to an HTTP service on behalf of a resource owner. It orchestrates an approval interaction where the user grants specific permissions to the application without ever sharing their credentials with it. This protocol's core purpose is the secure delegation of authority for accessing protected resources, making it an authorization framework rather than an authentication protocol for the end-user.

Why this answer

OAuth 2.0 is an authorization framework, not an authentication protocol, and it defines grant types such as authorization code, client credentials, implicit, and resource owner password credentials. It issues access tokens that grant scoped permissions to resources, deliberately leaving user identity verification to other layers. This is why OAuth 2.0 is the correct answer for a protocol designed specifically for authorization.

Exam trap

CISSP often tests the OAuth-versus-OIDC confusion, and the trap is selecting OpenID Connect because candidates conflate 'authorization' with 'authentication' and forget that OIDC is the authentication layer built on OAuth.

How to eliminate wrong answers

Option A (SAML 2.0) is wrong because SAML is primarily an authentication and single sign-on protocol that asserts user identity via XML assertions, not a delegated authorization framework with grant types. Option B (OpenID Connect) is wrong because OIDC is an authentication layer built on top of OAuth 2.0 that adds an ID token to verify user identity, so it is not 'authorization only.' Option C (Kerberos) is wrong because Kerberos is a ticket-based authentication protocol for network services, not an authorization framework with grant types like authorization code or client credentials.

36
MCQmedium

In Kerberos authentication, which component issues a Ticket Granting Ticket (TGT) after verifying the user's credentials?

A.Domain Controller
B.Ticket Granting Server (TGS)
C.Key Distribution Center (KDC)
D.Authentication Server (AS)
AnswerD

The Authentication Server (AS) is the precise Kerberos component responsible for the initial authentication of a user or service principal. Upon successful authentication, typically involving a shared secret (like a password hash), the AS issues a Ticket Granting Ticket (TGT) to the client. This TGT is then used by the client to request service tickets from the Ticket Granting Server (TGS) without needing to re-authenticate with the AS, streamlining subsequent access.

Why this answer

In Kerberos, the Authentication Server (AS) is the component that verifies the user's credentials (typically by decrypting a timestamp with the user's long-term key) and issues the Ticket Granting Ticket (TGT). The AS is part of the Key Distribution Center (KDC), but it is specifically the AS that performs authentication and returns the TGT. This makes Authentication Server the correct answer.

Exam trap

CISSP often tests the confusion between the KDC (the overall service) and the AS (the specific component that issues the TGT), causing candidates to pick KDC or TGS instead of Authentication Server.

How to eliminate wrong answers

Option A is wrong because Domain Controller is the Windows server role that hosts the KDC, but it is not the specific Kerberos component that issues the TGT. Option B is wrong because the Ticket Granting Server (TGS) issues service tickets after the client presents a valid TGT; it does not issue the TGT itself. Option C is wrong because the Key Distribution Center (KDC) is the overarching service that includes both the AS and TGS; while the KDC hosts the AS, the question asks for the specific component that issues the TGT, which is the AS.

37
MCQeasy

In LDAP, what does the Distinguished Name (DN) uniquely identify?

A.An entry in the directory
B.The root of the directory
C.The schema of the directory
D.A group within the directory
AnswerA

The Distinguished Name (DN) serves as the unique identifier for every individual entry within an LDAP directory. It specifies the exact, unambiguous path from the root of the Directory Information Tree (DIT) down to that specific entry, composed of a sequence of Relative Distinguished Names (RDNs). This hierarchical naming ensures that no two entries can share the same DN, guaranteeing absolute uniqueness across the entire directory and enabling precise referencing for all operations.

Why this answer

In LDAP, the Distinguished Name (DN) is a globally unique identifier for a single entry in the directory, composed of a sequence of Relative Distinguished Names (RDNs) that describe the entry's path from the leaf to the root. For example, cn=John Doe,ou=Users,dc=example,dc=com uniquely identifies one entry. The DN is used in bind operations, search base specifications, and modify operations to target a specific entry.

Exam trap

CISSP often tests whether candidates understand LDAP naming hierarchy — the trap is confusing the DN (a specific entry) with the base DN (the root suffix) or with the schema that governs the directory.

How to eliminate wrong answers

Option B is wrong because the root of the directory is identified by the base DN (e.g., dc=example,dc=com), which is a suffix of an entry's DN, not the DN itself. Option C is wrong because the schema defines the object classes and attribute types allowed in the directory, not the identity of an entry. Option D is wrong because a group is just one type of entry; a DN can identify a user, group, printer, or any other object, so 'a group' is too narrow and not the definition of a DN.

38
MCQeasy

Which principle ensures that a user is granted only the permissions necessary to perform their job functions?

A.Need-to-know
B.Least privilege
C.Separation of duties
D.Zero standing privileges
AnswerB

The principle of least privilege mandates that users, programs, or processes are granted only the absolute minimum set of permissions or access rights required to perform their legitimate tasks and nothing more. This fundamental security practice minimizes the attack surface by reducing the potential damage from accidental errors, insider threats, or successful external attacks, as compromised accounts have severely limited capabilities. It directly ensures a user is granted only the necessary permissions.

Why this answer

Least privilege is the principle that users should be granted only the minimum permissions necessary to perform their job functions, reducing the attack surface and limiting potential damage from accidental or malicious actions. The question explicitly describes granting only necessary permissions, which is the definition of least privilege. This principle is a core tenet of access control and is widely tested in security certifications.

Exam trap

CISSP often tests the confusion between least privilege and need-to-know; candidates may select need-to-know when the scenario emphasizes job function permissions rather than specific data access.

How to eliminate wrong answers

Option A is wrong because need-to-know is a subset of least privilege that focuses on data access based on specific information requirements, not on overall permissions for job functions. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud, rather than limiting permissions to job needs. Option D is wrong because zero standing privileges is a just-in-time access model where users have no persistent permissions, which is a specific implementation of least privilege but not the general principle described.

39
MCQhard

A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?

A.Golden ticket attack
B.Pass-the-ticket attack
C.Silver ticket attack
D.Kerberos brute force attack
AnswerA

Forging a TGT with the KRBTGT account hash lets an attacker mint arbitrary Kerberos tickets, including domain admin privileges, without authenticating. This is the defining mechanism of a golden ticket, which grants persistent, forged access to the entire domain.

Why this answer

A Golden Ticket attack occurs when an attacker compromises the KRBTGT account's password hash and uses it to forge a legitimate-looking Kerberos Ticket Granting Ticket (TGT). Because the KRBTGT account signs all TGTs in the domain, a forged TGT is trusted by every Kerberos-enabled service, granting the attacker persistent domain-wide access — often as domain admin — without needing to authenticate normally.

Exam trap

CISSP often tests the distinction between Golden Ticket (KRBTGT hash, forges TGT, domain-wide) and Silver Ticket (service account hash, forges TGS, single service), so candidates who confuse the two ticket types pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because Pass-the-ticket involves stealing and reusing a valid existing Kerberos ticket (TGT or service ticket) from memory, not forging a new one with the KRBTGT hash. Option C is wrong because a Silver ticket attack forges a service ticket (TGS) using the target service account's hash, granting access only to that specific service, not domain-wide admin. Option D is wrong because Kerberos brute force is an online password-guessing attack against the KDC, not a ticket-forging technique.

40
MCQhard

An organization implements Privileged Access Management (PAM) and wants to reduce the risk of standing privileges. Which approach grants temporary elevated access only when needed?

A.Session recording
B.Password vaulting
C.Break-glass accounts
D.Just-in-time access
AnswerD

Just-in-time (JIT) access is a core principle of modern Privileged Access Management that grants elevated privileges to users only when they are needed, for the specific task at hand, and for a strictly limited duration. This approach significantly reduces the attack surface by minimizing the time privileged accounts exist with standing access. Once the task is completed or the time limit expires, the elevated privileges are automatically revoked, aligning perfectly with the goal of managing privilege duration.

Why this answer

Just-in-time (JIT) access grants elevated privileges only for a limited time when a user requests and is approved for them, which directly reduces standing privileges. This matches the requirement to provide temporary elevated access only when needed.

Exam trap

CISSP often tests the difference between monitoring controls and access-granting controls, so the trap is selecting session recording or password vaulting when the question asks for temporary elevation.

How to eliminate wrong answers

Option A is wrong because session recording is a monitoring and audit control, not an access-granting mechanism. Option B is wrong because password vaulting stores and checks out credentials but does not by itself enforce time-bound elevation. Option C is wrong because break-glass accounts are emergency fallback accounts with standing high privileges, which increases rather than reduces standing privilege risk.

41
MCQeasy

Which of the following is a lightweight directory access protocol used for accessing and maintaining distributed directory information?

A.OAuth
B.LDAP
C.Kerberos
D.SAML
AnswerB

LDAP (Lightweight Directory Access Protocol) is an open, vendor-neutral, industry-standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network. It provides a standardized method for clients to query and update information in a directory, such as user accounts, groups, and network resources. Its "lightweight" designation refers to its streamlined design compared to its predecessor, X.500 DAP, making it efficient for common directory operations.

Why this answer

LDAP (Lightweight Directory Access Protocol) is specifically designed for accessing and maintaining distributed directory information services over an IP network. It operates on a client-server model, allowing queries and modifications to directory entries organized in a hierarchical structure (DIT). LDAP is an open standard and is widely used for authentication and authorization in enterprise environments, such as Microsoft Active Directory and OpenLDAP.

Exam trap

CISSP often tests the confusion between authentication protocols (like Kerberos) and directory access protocols (like LDAP), causing candidates to select Kerberos when asked about directory services.

How to eliminate wrong answers

Option A is wrong because OAuth is an authorization framework for granting third-party applications limited access to user resources without sharing credentials, not a directory access protocol. Option C is wrong because Kerberos is a network authentication protocol that uses tickets to allow nodes to prove their identity securely, but it does not provide directory access or maintenance. Option D is wrong because SAML is an XML-based framework for exchanging authentication and authorization data between parties, typically for single sign-on, not for accessing directory information.

42
MCQmedium

A financial application requires two employees to authorize a wire transfer. Which principle does this implement?

A.Least privilege
B.Separation of duties
C.Need-to-know
D.Zero standing privileges
AnswerB

Separation of duties (SoD) is an administrative control designed to prevent fraud, error, and abuse by distributing critical functions and responsibilities among multiple individuals. This ensures that no single person has complete control over an entire sensitive process, requiring collusion to compromise it. The scenario, demanding two employees to authorize a financial transaction, is a direct and classic implementation of SoD, as it mandates shared responsibility for a high-risk action.

Why this answer

Separation of duties (SoD) is the principle that requires two or more individuals to complete a sensitive transaction, such as a wire transfer, to prevent fraud or error. By mandating two employees to authorize the transfer, the application ensures no single person has unchecked control over the entire process, enforcing a dual-control mechanism. This directly implements the SoD principle, which is a core access control concept in identity and access management.

Exam trap

The trap here is that candidates confuse separation of duties with least privilege, thinking that limiting permissions alone achieves the same goal, but least privilege does not prevent a single user from performing all steps of a critical process.

How to eliminate wrong answers

Option A is wrong because least privilege grants users only the minimum permissions needed to perform their job, but it does not require multiple people to authorize a single action; that is a separate control. Option C is wrong because need-to-know restricts access to information based on necessity for a specific task, not the collaborative authorization of a transaction. Option D is wrong because zero standing privileges (ZSP) removes persistent access rights and grants them just-in-time, but it does not inherently enforce dual authorization for a single operation.

43
Multi-Selecthard

An organization is implementing OpenID Connect (OIDC) for authentication. Which THREE of the following are components of OIDC? (Choose three.)

Select 3 answers
A.Authorization code flow
B.Kerberos ticket granting ticket
C.UserInfo endpoint
D.SAML assertion
E.ID token
AnswersA, C, E

The Authorization Code flow is the most secure and widely recommended OAuth 2.0 flow for confidential clients, such as web applications, within OpenID Connect. It involves the client redirecting the user's browser to the authorization server, receiving a temporary authorization code, and then exchanging this code directly with the authorization server's token endpoint for ID and access tokens. This method prevents sensitive tokens from being exposed in the user's browser or URL, enhancing security significantly.

Why this answer

OIDC defines the Authorization Code Flow (option A) as one of its core authentication flows, where the client exchanges an authorization code at the token endpoint for an ID token and access token, making it a standard OIDC component. The UserInfo endpoint (option C) is a defined OIDC endpoint that returns claims about the authenticated end-user when presented with a valid access token, so it is part of the OIDC specification. The ID token (option E) is the central OIDC artifact—a signed JWT containing authentication claims such as iss, sub, aud, exp, and iat—that proves the user's identity to the client.

Kerberos ticket granting tickets (option B) belong to the Kerberos protocol, not OIDC, and SAML assertions (option D) are part of the SAML 2.0 standard, which is a separate federation protocol from OIDC.

Exam trap

CISSP often tests the confusion between OIDC and other authentication protocols like SAML and Kerberos, leading candidates to select SAML assertion or Kerberos TGT as OIDC components.

44
MCQmedium

An employee leaves the company, and their user account is not disabled. This creates a security risk known as:

A.Orphaned account
B.Insider threat
C.Privilege creep
D.Separation of duties violation
AnswerA

When an employee departs an organization and their associated user account remains active in the identity provider or directory services without an assigned owner, it is classified as an orphaned account. These accounts pose significant security risks as they lack accountability and are prime targets for unauthorized access or exploitation.

Why this answer

An orphaned account is a user account that remains active in the identity management system after the employee has left the organization. This creates a security risk because the account can be exploited by attackers or former employees to gain unauthorized access to systems, data, or network resources, bypassing access controls that rely on account deactivation.

Exam trap

The trap here is that candidates may confuse 'orphaned account' with 'insider threat' because both involve a former employee, but the question specifically asks for the name of the security risk created by the account itself, not the general threat category.

How to eliminate wrong answers

Option B is wrong because an insider threat is a broader category of risk posed by individuals within the organization (current or former) who misuse their access, but the specific risk of an account not being disabled after departure is defined as an orphaned account. Option C is wrong because privilege creep refers to the gradual accumulation of excessive permissions over time for a user who remains employed, not to an account left active after termination. Option D is wrong because a separation of duties violation occurs when a single user is allowed to perform conflicting tasks (e.g., both creating and approving a purchase order), which is unrelated to the failure to disable a departed user's account.

45
MCQmedium

Which OAuth 2.0 grant type is recommended for a public client (e.g., single-page application) that cannot securely store a client secret?

A.Resource owner password credentials grant
B.Authorization code grant with PKCE
C.Implicit grant
D.Client credentials grant
AnswerB

The Authorization Code Grant with Proof Key for Code Exchange (PKCE) is the recommended flow for public clients, such as mobile and single-page applications. PKCE mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and a `code_challenge` derived from it. This ensures that only the legitimate client that initiated the authorization request can exchange the authorization code for an access token, even if the code is intercepted.

Why this answer

Authorization Code grant with PKCE (Proof Key for Code Exchange, RFC 7636) is the OAuth 2.0 best current practice for public clients like SPAs and mobile apps that cannot keep a client secret confidential. PKCE adds a dynamically generated code_verifier and its hashed code_challenge to the authorization request, so even if the authorization code is intercepted, it cannot be exchanged without the verifier. This mitigates authorization code interception attacks that plague public clients.

Exam trap

CISSP often tests the outdated belief that the Implicit grant is appropriate for SPAs — the trap is selecting Implicit because it was historically recommended for browser apps, when modern guidance (RFC 8252, OAuth 2.1) mandates Authorization Code with PKCE.

How to eliminate wrong answers

Option A is wrong because the Resource Owner Password Credentials grant requires the app to handle the user's username and password directly, which is deprecated in OAuth 2.1 and violates the principle that credentials should only be entered into the authorization server's UI. Option C is wrong because the Implicit grant returns tokens directly in the URL fragment, exposing them to browser history, referrer headers, and XSS; it is deprecated in favor of Authorization Code + PKCE. Option D is wrong because the Client Credentials grant is for machine-to-machine (confidential) clients with no user context — it cannot be used by a public SPA acting on behalf of a user.

46
MCQhard

An organization is implementing identity management and wants to ensure that when an employee leaves, all access is promptly revoked. Which process is most directly responsible for removing accounts and access rights for a leaver?

A.Privileged access management
B.Access recertification
C.Deprovisioning
D.Separation of duties
AnswerC

Deprovisioning is the critical phase within the identity and access management (IAM) lifecycle that systematically revokes all access rights and disables or deletes user accounts when an individual's relationship with the organization ends or their role changes significantly. This process ensures that former employees or contractors can no longer access corporate resources, mitigating the risk of unauthorized access and data breaches. Effective deprovisioning involves removing access across all connected systems, applications, and physical access controls in a timely and comprehensive manner.

Why this answer

Deprovisioning is the process of removing user accounts and access rights when an employee leaves the organization. It directly addresses the requirement to promptly revoke all access, ensuring that the former employee cannot authenticate or authorize any actions within the system. This process typically involves disabling or deleting the user object in the directory service (e.g., Active Directory) and removing associated permissions from all resources.

Exam trap

The trap here is that candidates may confuse 'Access Recertification' (a periodic review) with the immediate revocation action required for a leaver, or think 'Privileged Access Management' covers all account removal, when it only addresses high-privilege accounts.

How to eliminate wrong answers

Option A is wrong because Privileged Access Management (PAM) focuses on controlling and monitoring access for privileged accounts (e.g., administrators), not on the general removal of all accounts for a leaver. Option B is wrong because Access Recertification is a periodic review process to validate that existing access rights are still appropriate, not an immediate action to remove access upon termination. Option D is wrong because Separation of Duties is a control principle that prevents conflicts of interest by dividing critical tasks among multiple people, not a process for revoking accounts.

47
Multi-Selectmedium

In the context of identity management, which TWO of the following are risks associated with orphaned accounts? (Choose two.)

Select 2 answers
A.Compliance violations
B.Reduced system performance
C.Unauthorized access by former employees
D.Enhanced audit logging
E.Increased help desk calls
AnswersA, C

Regulatory frameworks such as HIPAA, PCI-DSS, and SOX mandate strict access control policies, including the prompt deprovisioning of inactive or terminated user accounts. Failing to identify and disable these orphaned accounts directly violates compliance requirements, potentially resulting in severe financial penalties, failed audits, and legal liabilities for the organization.

Why this answer

Option A (Compliance violations) is correct because orphaned accounts—accounts with no valid owner or associated active user—violate regulatory requirements such as SOX, HIPAA, and GDPR, which mandate that access be attributable to a known, authorized individual and that accounts be reviewed and revoked promptly; auditors treat unowned accounts as a control failure. Option C (Unauthorized access by former employees) is correct because orphaned accounts often persist after an employee leaves or changes roles, and since the credentials may still be valid and unmonitored, a former employee (or anyone who obtains those credentials) can use them to access systems without authorization. Option B (Reduced system performance) is not a typical identity-management risk of orphaned accounts; performance impact is not the concern here.

Option D (Enhanced audit logging) is the opposite of a risk—orphaned accounts actually degrade auditability rather than enhance it. Option E (Increased help desk calls) is not a recognized risk category for orphaned accounts; it is unrelated to the access-control and compliance issues at stake.

Exam trap

CISSP often tests the difference between a risk caused by a weakness (orphaned accounts → unauthorized access, compliance violations) and a control that mitigates it (audit logging) — candidates who pick 'enhanced audit logging' confuse a detective control with a risk.

48
MCQhard

An organization wants to provide just-in-time administrative access to servers, with session recording and password vaulting. Which solution is best suited?

A.Privileged Access Management (PAM)
B.Identity as a Service (IDaaS)
C.Single Sign-On (SSO)
D.Role-Based Access Control (RBAC)
AnswerA

Privileged Access Management (PAM) solutions are specifically engineered to secure, manage, and monitor highly sensitive administrative accounts and access to critical systems. They enforce just-in-time (JIT) access, granting elevated permissions only when an administrator needs them for a specific task and for a limited duration, thereby significantly minimizing the attack surface. PAM also typically includes essential features like session recording, password vaulting, and comprehensive audit trails, which are crucial for compliance and incident response related to high-risk administrative operations.

Why this answer

PAM (Privileged Access Management) solutions are purpose-built to broker, vault, and record privileged sessions — providing just-in-time elevation, credential checkout, and full session recording for administrative access to servers. Tools like CyberArk, BeyondTrust, and Delinea implement these controls natively, matching every requirement in the scenario. The other options address authentication or authorization but lack session recording and password vaulting capabilities.

Exam trap

CISSP often tests the distinction between authentication/authorization controls (SSO, RBAC) and privileged session management — candidates pick SSO or RBAC because they sound like access control, missing the vaulting and recording requirements unique to PAM.

How to eliminate wrong answers

Option B is wrong because IDaaS provides cloud-based identity federation and SSO for applications, not privileged session brokering, vaulting, or recording. Option C is wrong because SSO only centralizes authentication across apps — it does not vault privileged credentials or record administrative sessions. Option D is wrong because RBAC is an authorization model that assigns permissions by role; it does not provide just-in-time elevation, credential vaulting, or session recording.

49
MCQeasy

Which of the following is a process that ensures users periodically confirm they still need access to systems and data?

A.Deprovisioning
B.Separation of duties
C.Recertification
D.Provisioning
AnswerC

Recertification is the essential periodic process of formally reviewing and validating that users' current access rights and privileges remain appropriate and necessary for their assigned job functions. This proactive measure ensures adherence to the principle of least privilege over time, identifying and remediating instances of 'privilege creep' where users accumulate excessive permissions. It significantly reduces the organization's attack surface by eliminating unnecessary access.

Why this answer

Recertification is the process where users periodically confirm that they still require access to systems and data. It involves reviewing user accounts and permissions to ensure they remain appropriate, often as part of access control audits. This directly matches the description.

Exam trap

CISSP often tests the confusion between recertification and deprovisioning; candidates may think deprovisioning includes periodic reviews, but deprovisioning is the actual removal of access, while recertification is the review that may trigger it.

How to eliminate wrong answers

Option A (Deprovisioning) is wrong because it is the removal of access when no longer needed, not the periodic confirmation of need. Option B (Separation of duties) is wrong because it is a preventive control that divides tasks among multiple users to prevent fraud, not an access review process. Option D (Provisioning) is wrong because it is the initial granting of access, not the periodic review.

50
MCQmedium

In LDAP, which attribute uniquely identifies an entry within the directory information tree?

A.Distinguished Name (DN)
B.Relative Distinguished Name (RDN)
C.Organizational Unit (OU)
D.Common Name (CN)
AnswerA

The Distinguished Name (DN) serves as the absolute and unambiguous identifier for every entry within an LDAP directory. It is a sequence of Relative Distinguished Names (RDNs) that traces a unique path from the root of the directory information tree (DIT) down to the specific entry. This hierarchical structure ensures that no two entries can possess the exact same DN, guaranteeing global uniqueness across the entire LDAP directory service.

Why this answer

The Distinguished Name (DN) is the full path from the root of the directory information tree to the entry, uniquely identifying it across the entire directory. It includes the RDN plus all superior entries, ensuring global uniqueness.

Exam trap

CISSP often tests the confusion between DN and RDN; candidates may think RDN is globally unique, but it's only unique within its parent, so the full DN is required for global uniqueness.

How to eliminate wrong answers

Option B is wrong because the Relative Distinguished Name (RDN) is only unique within its immediate parent and does not provide a full path. Option C is wrong because an Organizational Unit (OU) is a container object, not an attribute that uniquely identifies an entry. Option D is wrong because a Common Name (CN) is just one component of an RDN and may not be unique across the directory.

51
Multi-Selectmedium

A financial services firm is deploying a customer-facing mobile banking app and wants to delegate limited access to account balances and transaction history to third-party budgeting apps without sharing the customer's banking credentials. The security architect must select controls that implement this delegation securely. (Choose two.)

Select 2 answers
A.Use OAuth 2.0 authorization code grant with PKCE so the budgeting app obtains a scoped access token without receiving the customer's password.
B.Configure the budgeting app to store the customer's banking username and password in its local keystore for future API calls.
C.Rely on SAML 2.0 bearer assertions issued to the budgeting app so it can impersonate the customer for all banking operations.
D.Issue refresh tokens with long lifetimes and broad scopes so budgeting apps can maintain access without repeated customer consent.
E.Define granular OAuth 2.0 scopes such as read:balances and read:transactions and require the customer to consent to them during authorization.
AnswersA, E

The authorization code grant with PKCE lets the budgeting app obtain a limited access token after the customer authenticates directly with the bank, so credentials are never shared. PKCE protects the code exchange from interception on public clients such as mobile apps, matching the delegation and security requirements of this scenario.

Why this answer

OAuth 2.0 authorization code grant with PKCE lets the budgeting app receive a scoped token without ever handling the customer's credentials, and granular scopes plus explicit consent constrain that token to balances and transaction history. Together these controls implement least-privilege delegation for a public mobile client while keeping the bank's authentication boundary intact.

Exam trap

The trap here is confusing authentication with authorization delegation, leading to choices that share credentials or issue overly broad tokens instead of scoped OAuth access.

52
MCQmedium

A financial institution requires that no single employee can approve a transaction and also reconcile the account. This is an example of which security principle?

A.Separation of duties
B.Least privilege
C.Defense in depth
D.Need to know
AnswerA

Separation of duties is a control designed to prevent fraud, error, and abuse by ensuring that no single individual has complete control over a critical process from start to finish. It mandates that different individuals perform distinct parts of a sensitive task, such as authorizing, recording, and reconciling transactions. This structure prevents a single employee from both initiating and approving a financial transaction, thereby mitigating the risk of unauthorized actions.

Why this answer

Separation of duties (SoD) is the security principle that prevents a single individual from having conflicting responsibilities, such as both approving a transaction and reconciling the account. This reduces the risk of fraud or error by requiring collusion between two or more people to subvert a process. In a financial system, SoD is enforced through access control mechanisms that assign distinct roles (e.g., 'Transaction Approver' and 'Account Reconciler') with mutually exclusive permissions, often implemented via Role-Based Access Control (RBAC) or attribute-based policies.

Exam trap

The trap here is that candidates confuse 'separation of duties' with 'least privilege' because both involve limiting access, but separation of duties specifically addresses conflicting tasks to prevent fraud, not just minimizing permissions.

How to eliminate wrong answers

Option B (Least privilege) is wrong because it focuses on granting only the minimum permissions necessary to perform a job function, not on preventing conflicts of interest or fraud through role separation. Option C (Defense in depth) is wrong because it describes a layered security strategy using multiple controls (e.g., firewalls, IDS, encryption), not a principle that divides critical tasks among different individuals. Option D (Need to know) is wrong because it restricts access to data based on whether it is required for a specific task, but does not address the segregation of conflicting duties like approval and reconciliation.

53
MCQmedium

A security analyst is reviewing access rights and discovers an active account belonging to a former employee who left six months ago. This is an example of:

A.Orphaned account
B.Separation of duties violation
C.Account lockout
D.Privilege escalation
AnswerA

An orphaned account is a user or service account that no longer has an active, accountable owner or associated employee, often due to an employee's departure without proper deprovisioning. When a security analyst discovers such an account during an access rights review, it represents a significant security vulnerability as it could be exploited without detection or used to maintain unauthorized access. These accounts pose a risk because they lack oversight and may retain elevated privileges, making them prime targets for malicious actors. Identifying them is a critical part of regular access reviews and identity lifecycle management.

Why this answer

An orphaned account is one that remains active after its owner no longer needs it — typically because the employee left, changed roles, or the account was never deprovisioned. A former employee's account still active six months after departure is the textbook definition of an orphaned account. It represents a significant access control failure because the account can be used without legitimate ownership.

Exam trap

The trap is conflating 'orphaned account' with 'insider threat' or 'privilege escalation'; the exam wants you to identify the specific access-control condition (unmanaged leftover account) rather than the broader risk category.

How to eliminate wrong answers

Option B is wrong because separation of duties violations involve one person holding conflicting responsibilities, not an unmanaged leftover account. Option C is wrong because account lockout is a state where an account is temporarily disabled after failed logins, which is unrelated to a departed employee's active account. Option D is wrong because privilege escalation refers to gaining higher privileges than authorized, not to the mere existence of an unmanaged account.

Ready to test yourself?

Try a timed practice session using only Identity and Access Management questions.