Courseiva

CISSP · topic practice

Identity and Access Management practice questions

Identity and Access Management covers authentication, authorization, and identity lifecycle controls: Kerberos, federation, OAuth/OIDC, SAML, access control models, and provisioning. CISSP tests your ability to select the right control for a scenario, distinguish authentication from authorization, and recognize attacks like Kerberos ticket forgery, credential stuffing, and privilege escalation through misconfigured trust.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Identity and Access Management

What the exam tests

What to know about Identity and Access Management

Map each scenario to the correct identity control: identify the attack (golden ticket, pass-the-hash), select the access model matching the described ownership, and choose the OAuth grant fitting the client type. The single most important thing: separate authentication from authorization before answering.

Kerberos flows: AS, TGT, TGS, service tickets, and KRBTGT golden ticket forgery

Access control models: DAC, MAC, RBAC, ABAC, and rule-based authorization decisions

OAuth 2.0 grant types, OpenID Connect, SAML assertions, and PKCE for public clients

Identity lifecycle: provisioning, deprovisioning, federation, SSO, and privileged access management

Watch out for

Common Identity and Access Management exam traps

  • ▸Confusing authentication (proving identity) with authorization (granting permissions), which flips scenario answers.
  • ▸Choosing MAC when the scenario describes a resource owner setting permissions, which is DAC.
  • ▸Picking the implicit or password grant for mobile apps instead of authorization code with PKCE.

Practice set

Identity and Access Management questions

20 questions · select your answer, then reveal the explanation

An organization requires users to authenticate with a password and a one-time code sent to their mobile phone. This is an example of which authentication method?

Which statement about SAML 2.0 is correct?

A security architect is designing a Single Sign-On (SSO) solution for a web application that needs to support authentication and authorization. Which TWO of the following protocols are best suited for this purpose? (Select TWO)

An organization is implementing Privileged Access Management (PAM). Which THREE of the following are common features of a PAM solution? (Select THREE)

In Kerberos, which component issues ticket-granting tickets (TGTs) after verifying the user's credentials?

An attacker has obtained a Kerberos TGT and uses it to request service tickets for any resource in the domain. Which type of attack is this?

A company implements a policy requiring two different employees to approve a payment transaction. This is an example of:

An organization uses Active Directory and needs to enforce password complexity settings for all users in a specific department. What is the most efficient way to achieve this?

Which of the following is an example of a Type 2 authentication factor?

Which of the following access control models allows the data owner to decide who can access their resources?

Which authentication factor type is a smart card?

In Kerberos authentication, which component issues a Ticket Granting Ticket (TGT) after verifying the user's credentials?

An attacker who has compromised the Kerberos Key Distribution Center (KDC) could forge a Ticket Granting Ticket (TGT) to impersonate any user. This type of attack is known as:

Which OAuth 2.0 grant type is recommended for a public client (e.g., single-page application) that cannot securely store a client secret?

OpenID Connect (OIDC) extends OAuth 2.0 primarily by adding which capability?

An organization is implementing identity management and wants to ensure that when an employee leaves, all access is promptly revoked. Which process is most directly responsible for removing accounts and access rights for a leaver?

A security analyst is reviewing access rights and discovers an active account belonging to a former employee who left six months ago. This is an example of:

In a Privileged Access Management (PAM) solution, which feature provides temporary elevation of privileges for specific tasks, reducing the risk of standing privileges?

In LDAP, what does the Distinguished Name (DN) uniquely identify?

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Identity and Access Management sessions

Start a Identity and Access Management only practice session

Every question in these sessions is drawn from the Identity and Access Management domain — nothing else.

Related practice questions

Related CISSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISSP exam test about Identity and Access Management?
Map each scenario to the correct identity control: identify the attack (golden ticket, pass-the-hash), select the access model matching the described ownership, and choose the OAuth grant fitting the client type. The single most important thing: separate authentication from authorization before answering.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Identity and Access Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Identity and Access Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISSP topics?
Use the topic links above to move to related areas, or go back to the CISSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISSP exam covers. They are not copied from any real exam or dump site.