All questions

CISSP Domain 5 Identity and Access Management Practice Test

Browse all practice questions for the CISSP Domain 5 Identity and Access Management Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 5 Identity and Access Management Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which of the following statements about rights is true?
  • What is the primary function of access badges in a secured facility?
  • What is the main disadvantage of biometric systems regarding enrollment time?
  • Which biometric characteristic is known for remaining the same throughout a person's life?
  • Which protocol is primarily designed for authorization in web applications?
  • In identity management, what is the purpose of Directory Synchronization?
  • How does implicit deny enhance system security?
  • What tool can Jim use to allow cloud-based applications to access data on his behalf?
  • Which of the following best describes the function of an Identity Provider (IdP)?
  • What is a primary weakness of the SESAME authentication process?
  • Which cryptographic method does Kerberos utilize?
  • What role does OAuth 2.0 play in tech systems?
  • What is the function of Physical Access Control Systems (PACS)?
  • After performing an IP probe, what is the next step typically taken by an attacker?
  • What is the term for access control that allows user-defined settings?
  • A key feature of role-based access control (RBAC) is:
  • When configuring biometric systems, what does the CER (cross-over error rate) represent?
  • In which type of role-based access control is the role applied to multiple applications based on the user's position in the organization?
  • What type of control involves restricting access based on the internal data of each field?
  • What type of access control scheme limits access based on security labels assigned to resources?
  • What protocol should Angela monitor to read traffic from a RADIUS server configured with default settings?
  • Callback to a home phone number is an example of what type of authentication factor?
  • What is the primary purpose of SAML 2.0?
  • Role-Based Access Control (RBAC) is based on what principle?
  • Which type of attack targets statistical weaknesses in a cryptosystem?
  • What is the function of the Key Distribution Center (KDC) in Kerberos?
  • Which authentication protocol is primarily used by Windows systems?
  • Which roles are defined in the SAML Specification 2.0?
  • What is the primary feature of Single Sign-On (SSO) technology?
  • What service does IDaaS primarily provide for users accessing SaaS applications?
  • Why is HAVAL not classified as an encryption algorithm?
  • What makes longer passwords more effective?
  • What is the primary function of Kerberos in network security?
  • What does Service Provisioning Markup Language (SPML) specifically relate to?
  • What is a potential outcome of improperly applying separation of duties?
  • Which scenario best describes Federation?
  • What password requirement will have the highest impact in preventing brute force attacks?
  • Which of the following best describes the role of vulnerability scans in cybersecurity?
  • When an application allows a logged-in user to perform specific actions, it is an example of what?
  • What type of access control is composed of policies and procedures that support regulations and organizational requirements?
  • How does increasing password complexity impact security?
  • In a lattice-based access control model, what do all objects and subjects have?
  • To enhance security for RADIUS, how should Brian implement encryption?
  • Which of the following access control methods allows task-based controls to determine access?
  • Which attribute is typically NOT used for user identity management in social identity systems?
  • What type of attack is intended to be prevented by the creation and exchange of state tokens?
  • What is the first step in the Kerberos logon process?
  • What is Kathleen's best option to ensure the users of the passcards are who they are supposed to be?
  • Which technology ensures a user can authenticate once and gain access to multiple systems?
  • What is the common target for attackers when they perform port scans?
  • Which of the following is a function of a Trusted Platform Module (TPM)?
  • What is a common method for managing Constrained Interface Applications?
  • What does an increase in the Crossover Error Rate (CER) signify for a biometric authentication system?
  • Which encryption methods does SESAME utilize?
  • What does the Nmap tool primarily identify when it scans a system?
  • In a biometric access control system, what problem may occur if the system is set too high, like at point B?
  • Which term refers to the access granted for an object that determines what actions can be performed on it?
  • During an account review, which aspect is crucial for user access management?
  • In Non-Discretionary Access Control, who determines access rights?
  • RAID-5 is an example of which type of control?
  • What does "constrained interface" mean in the context of security applications?
  • Which of the following describes a virtual table created from specific columns of one or more database tables?
  • What is a typical use case for Rule-Based Access Control?
  • What protocol is commonly employed for authentication in wireless networks, modems, and network devices?
  • What do account management systems aim to streamline?
  • Which of the following is a central task of account management systems?
  • What is the main purpose of an Access Control System?
  • What solution is most likely to reduce help desk cases related to password changes?
  • What type of access control defines a subject's ability to access an object based on their assigned role or tasks?
  • What replaces NTLM in Windows environments?
  • Which of the following is a client/server protocol designed to allow network access servers to authenticate remote users?
  • What does the 'lattice-based' model in access controls primarily compartmentalize?
  • What is the purpose of a password checker program?
  • What is the key measurement in hand geometry biometrics?
  • What does binding a user to appropriate controls involve?
  • What does the False Acceptance Rate (Type II) represent in identity management?
  • What authentication factor does biometric authentication primarily rely on?
  • What are the four key principles of access control referred to as?
  • What does SSO stand for in the context of identity access management?
  • Which term best describes a rigid control over access adjustments?
  • What is the purpose of authorization in access management?
  • Which of the following is not considered a single sign-on (SSO) implementation?
  • How are permissions related to actions on files?
  • Who is considered a 'subject' in access management terms?
  • Which administration method may lack consistency in procedures?
  • What role does SYSKEY play in relation to hashed passwords on Windows?
  • Which of the following statements about vulnerability scanning is TRUE?
  • Voice pattern recognition is categorized under which type of authentication factor?
  • What does the authentication process involve?
  • What does Identity as a Service (IDaaS) provide?
  • When using SYSKEY on Windows systems, what is encrypted in the password store?
  • What concept involves the systematic assignment of access rights based on roles?
  • Which of the following is NOT an example of a vulnerability scanning tool?
  • Which open protocol was designed to replace RADIUS, providing extensible commands but lacking backward compatibility?
  • What type of process should a company perform to ensure that an employee has appropriate rights?
  • What does it mean if the Crossover Error Rate is achieved?
  • Which access control mechanism identifies users based on their identity and assigns resource ownership accordingly?
  • Which of the following is not a valid LDAP distinguished name (DN)?
  • What is indicated when a port is labeled 'open' during a port scan?
  • What is one primary characteristic of a static password?
  • What distinguishes an Access Control List (ACL) from a capability table?
  • In multi-factor authentication, what is the benefit of using multiple factors?
  • What does a MAC address signify in networking?
  • Which term describes an attack that uses a predefined list of words to guess passwords?
  • How does the SESAME process handle access privileges?
  • Which operation involves the allocation of access permissions to users?
  • Why is monitoring false acceptance and rejection rates important in identity management?
  • What technique allows users to be created and managed through an on-premises identity provider?
  • In a scenario where an organization requires multiple forms of login (username, PIN, password, and retina scan), how many distinct types of factors are being used?
  • What is a brute force attack?
  • Which of the following is not a common threat to access control mechanisms?
  • What happens to addresses that do not respond to an IP probe?
  • What defines a cryptographic device?
  • What defines the "exploit" in the context of vulnerability scanning?
  • Rule-based access control (RBAC) is characterized by:
  • What must a client do before using the Ticket Granting Ticket (TGT) in the Kerberos authentication process?
  • What does the Crossover Error Rate (CER) indicate in a biometric system?
  • In a Kerberos environment, what is sent to the Ticket Granting Service (TGS) for resource access?
  • Google's identity integration with various organizations and applications across domains is an example of what?
  • What does the Secure European System for Application in a Multi-Vendor Environment (SESAME) primarily utilize?
  • Fingerprints consist of which of the following features?
  • What term describes the situation where multiple processes require access to the same resource?
  • If an organization uses a combination of passwords and biometric data to control access, which type of authentication factors are being utilized?
  • What action are you performing when you input a user ID and password?
  • Which of the following types of access controls does NOT describe a lock?
  • What does IDaaS stand for?
  • What principle ensures that users are only granted access to information necessary for their tasks?
  • What does 'hybrid' administration signify in access management?
  • What is a Type 2 authentication factor?
  • Which option best describes the purpose of salting a password hash?
  • What is one benefit of using multiple vulnerability scanning tools?
  • What is the primary function of KRYPTOKNIGHT?
  • What type of identity proofing do questions like "What's your pet's name?" represent?
  • What two important elements does the KDC send to the client after verifying the user's credentials during the Kerberos logon process?
  • What type of vulnerabilities do statistical attacks often exploit?
  • What do we refer to when describing the biometric identification characteristic of "What you are"?
  • What do iris scans analyze?
  • Dog, guards, and fences are examples of what type of control?
  • What does a directory service typically provide?
  • What is the role of facility access control?
  • What is the name of the stored sample of a biometric characteristic?
  • Vulnerability scanning tools like Qualys are primarily used for what purpose?
  • What type of systems do Kerberos, KryptoKnight, and SESAME represent?
  • What is the primary method of securing passwords in a well-designed web application?
  • What authentication protocol does Windows use by default for Active Directory systems?
  • What is the main characteristic of single factor authentication?
  • Which standard is associated with directory services important for identity systems?
  • How does a static password token function in authentication?
  • Which of the following is a technique to add complexity to the encryption process?
  • What is the primary purpose of performing reconnaissance in a network attack?
  • The US government CAC is an example of which type of authentication factor?
  • Which access control is commonly utilized by firewalls?
  • Which error type in biometric systems is represented by the movement from legitimate access to unauthorized access?
  • What is a significant drawback of commonly used password generators?
  • When the e-commerce application creates an account for a Google+ user, where should that user's passwords be stored?
  • What type of biometric authenticator is palm scanning classified as?
  • Which of the following best describes a Type 3 authentication factor?
  • Which factor is NOT considered an advantage of biometric authentication?
  • Which access control type would incorporate mandatory restrictions based on clearance levels?
  • In which situation might an organization prefer a higher false rejection rate (FRR) over a higher false acceptance rate (FAR) in biometric systems?
  • What access control model best describes the limitation of a user not being able to use certain features in a system?
  • What do Keyboard Dynamics primarily focus on capturing?
  • Which biometric technology would be least favorable for identifying health conditions?
  • What strategy is commonly used in social engineering attacks?
  • What aspect of Active Directory is emphasized for security?
  • Mandatory Access Controls (MACs) require what for managing access?
  • Which of the following is a primary function of logging in accountability?
  • Which biometric method provides a one-to-many identification by storing full fingerprints?
  • In an access control system, what must be done each time a subject attempts to access an object?
  • What does Security Assertion Markup Language 2.0 (SAML 2.0) facilitate?
  • What is an example of a cognitive password?
  • How much additional complexity does adding a single character to the minimum length of passwords for an organization create?
  • What action should network administrators take concerning ping functionality?
  • Which access control model is based on the roles assigned to a user in an organization?
  • Which LDAP authentication mode can provide secure authentication?
  • What does Rule-Based Access Control (Rule-BAC) use to determine access on a system?
  • What type of attack can be mitigated by using a trusted path?
  • What is the best way to provide accountability for the use of identities?
  • Which entity typically manages password recovery processes for social identity applications?
  • If an attacker specifically wants to target a web server, which port is typically scanned?
  • What is a common feature of Access as a Service?
  • What does the principle of least privilege entail?
  • Discretionary Access Control (DAC) allows which individual to control access to an object?
  • What does electronic authentication (e-authentication) establish?
  • What type of service does IDaaS represent?
  • Which of the following best defines authorization?
  • What does accountability in a system ensure?
  • What does Access as a Service typically include?
  • What is the recommended option for handling on-site identity needs in an organization using Active Directory for AAA services?
  • What type of access control is illustrated by a permission listing for different users on a storage device?
  • Which characteristic is NOT a component of biometric authentication?
  • What is a significant disadvantage of SSO?
  • What does XACML specifically describe?
  • What is the main purpose of the Time-to-Live (TTL) setting in networking configurations?
  • Which model includes global rules that apply to all subjects?
  • What is a common use for TACACS+ in identity management?
  • What is one key advantage of implementing SSO?
  • Which identity management system method is primarily focused on web applications rather than traditional networks?
  • What does separation of duties and responsibilities aim to achieve?
  • What does 'control' imply in access management systems?
  • In the context of access management, what does 'access' refer to?
  • Which concept refers to the ability to modify system parameters like the system time?
  • What is the key function of a Password Management System in an enterprise environment?
  • During the Kerberos logon process, how is the user's username and password protected when sent to the KDC?
  • What is the function of HAVAL in the context of hashing?
  • What type of information does a vulnerability scan typically produce?
  • What is the main purpose of Multi-factor Authentication?
  • How prevalent are IP probes on the Internet today?
  • What best describes "privileges" in the context of access control?
  • What does the term 'triviality' refer to in password policies?
  • Which of the following AAA protocols is most commonly used in networking environments?
  • What does federated ID management relate to in an SSO context?
  • What is the primary function of a virtual directory?
  • What could be a result of decentralized administration in access management?
  • What is a defining characteristic of Logical Access Controls?
  • How does authentication contribute to identity management?
  • Which of the following controls can be considered a preventive measure against unauthorized access?
  • What is a major concern regarding the use of biometrics?
  • What is a characteristic of content-dependent access control?
  • What process is utilized by Susan's financial services company to verify user identity through past data?
  • What is the primary goal of registration in identity management?
  • In access management, what does 'object' refer to?
  • Which biometric system analyzes the unique characteristics of one's voice?
  • What is the primary goal of access control techniques?
  • Mandatory access control is based on what type of model?
  • What is the main focus of a capability table?
  • What is an example of a context-dependent control?
  • What does a 'closed' port status mean in the context of a network scan?
  • Which system is responsible for user authentication for Google+ users?
  • What type of access control model is being leveraged when Alex sets permissions on a Linux server?
  • Ben uses a software-based token that changes its code every minute. What type of token is he using?
  • What does the False Rejection Rate (Type I) indicate in authentication systems?
  • Which of the following items is not commonly associated with restricted interfaces?
  • Which of the following is not part of a Kerberos authentication system?
  • A sequence of login failures in logs indicates what type of attack?
  • What type of access control allows a file owner to manage access based on an access control list?
  • Which access control model restricts access based on user roles?
  • What is an important aspect of accountability in access management?
  • What differentiates voice prints from other biometric devices?
  • What is the goal of the Needham-Schroeder protocol used in SESAME?
  • What is an example of a consequence of not conducting regular vulnerability scans?
  • What is a primary purpose of implementing an access control list (ACL)?
  • What role does complexity play in password strength?
  • Which of the following is NOT considered an access control layer?
  • What is a passphrase most commonly used for?
  • What authentication technology complements OAuth for identity verification using a RESTful API?
  • What process involves verifying an individual’s identity in access management?
  • In password security, what does the term "exhaustive" often refer to?
  • Which biometric method scans the blood-vessel pattern of the retina?
  • Which of the following is a ticket-based authentication protocol designed to provide secure communication?
  • Which of the following types of scans is often performed in conjunction with vulnerability scanning?
  • What type of biometric error occurs if a user logs into another customer's account after scanning their fingerprint?
  • Which of the following are considered physical devices for Type 2 authentication?
  • What aspect does Hand Topology analyze?
  • Which type of applications restrict what users can do based on their privileges?
  • What is an example of a Type 1 authentication factor?
  • What is primarily needed for establishing trust between a user and a system?
  • What does a Password Management System accomplish?
  • In biometric systems, what does a higher false rejection rate indicate?
  • What is a thin client in the context of identity management?
  • What is the role of a User ID in a system?
  • What is the most widely used biometric method today?
  • In what format does OpenLDAP store the userPassword attribute by default?
  • What does it signify when Nmap encounters a 'filtered' port during a scan?
  • Which of the following best describes the term "authorization"?
  • What does multi-factor authentication aim to achieve?
  • Which pair of factors are key for user acceptance of biometric identification systems?
  • What standards-based markup language should Lauren choose to build her interface for provisioning services?
  • What is an essential feature of password management systems?
  • What is a common concern regarding the use of retina scans for biometric authentication?
  • What availability risk does onsite authentication create for traveling users accessing 3rd party applications?
  • In a discretionary access control model, what does the owner of an object do?
  • What is the main characteristic of Limited RBAC?
  • In a MAC model, which objects and subjects have a label?
  • Which classification levels of data can Jim access with his Secret clearance under mandatory access control?
  • Which framework allows third-party applications limited access to HTTP services?
  • Which of the following describes a behavioral biometric characteristic?
  • Which component of the KDC generates the encrypted time-stamped Ticket Granting Ticket (TGT)?
  • In the context of Identity Governance, what does SSO stand for?
  • Which service component does Identity as a Service typically provide?
  • What type of authentication factor is represented when using a fingerprint scanner?
  • What is one key benefit of using IDaaS?
  • In biometrics, what is the term used for the rate at which legitimate users are incorrectly rejected?
  • Which scanning tool is known for its ability to automate network vulnerability assessments?
  • What is the acceptable throughput time for biometric systems according to industry standards?
  • Which approach can help in managing user identities across different platforms and services?
  • Biba is what type of access control model?
  • What is SAML primarily used for?
  • What is the main function of a physical access control system?
  • What can be an outcome of failing to remediate vulnerabilities identified in a scan?
  • What is the main purpose of identity proofing?
  • Which aspect of Kerberos makes it a mature protocol?
  • Which biometric technology is considered most accurate?
  • What does port 636 indicate in Jim's LDAP client configuration?
  • What defines Rule-Based Access Control?
  • Which system uses pre-determined policies to control logical access?
  • Which of the following is a benefit of using Kerberos?
  • What type of password remains the same for each logon?
  • In the context of password security, what is the difference between a password checker and a password hacker?
  • What type of access control system is used when a table includes assigned privileges, objects, and subjects to manage access?
  • What issue does Lauren encounter when she has access to various systems that are unnecessary for her job?
  • How can policy checking improve password effectiveness?
  • What role do automated tools play in network reconnaissance?
  • Which of the following is not considered a weakness in Kerberos?
  • Which type of authentication method involves a time-based component between a token and an authentication server?
  • What is the main function of XML Signature?
  • What does a dimmed or disabled menu item indicate in a constrained interface?
  • When conducting a vulnerability scan, what is the first step an attacker typically performs?
  • Which control model uses policies to determine access rights but does not allow discretion by the user?
  • What is an essential feature of access control systems?
  • How is a unique identifier added to an identity system?
  • In terms of authentication factors, what does "something you are" refer to?
  • What does Discretionary Access Control (DAC) allow concerning the control of access?
  • What does validity of access control tokens depend on?
  • What is a distinctive characteristic of Rule-BAC models?
  • Which elements does a thin client approach encompass to guard a network?
  • When a subject claims an identity, what process is being performed?
  • What type of trust must be established to connect an Active Directory environment with an existing Kerberos K5 domain?
  • In a biometric system, what is the result when the False Acceptance Rate (FAR) is lower?
  • Which session management solutions can Ben recommend to prevent unauthorized access during lunch hours?
  • What type of biometric error occurred when a legitimate user is mistakenly rejected?
  • What method should Lauren use to validate user identities for a banking website?
  • What does Hybrid RBAC facilitate within an organization?
  • Which principle guarantees that a user will not gain unauthorized access to resources?
  • What type of administration allows only one element to configure access controls centrally?
  • How does the Kerberos client authenticate the server after receiving the TGT?
  • What is a potential risk when using social login for an e-commerce application?
  • When Cris adds a user ID to an identity system, what process has he completed?
  • Which access control scheme should Susan recommend for flexibility and scalability?
  • What psychological aspect represents a concern when applying biometric identification?
  • In ABAC, access rights are determined by what?
  • In palm scanning, what features are identified as unique to each individual?
  • In an LDAP distinguished name, which component becomes less specific as it progresses from left to right?
  • What is the primary purpose of logging in identity management?
  • What does a Trusted Platform Module (TPM) primarily provide?
  • What is the primary purpose of performing a vulnerability scan?
  • Which of the following is not considered a logical or technical access control?
  • In an identity-based access control system, who ultimately decides access rights?
  • Radio Frequency Identification (RFID) technology is primarily used for what purpose?
  • What is the primary goal of hacking?
  • Which technique involves probing all active systems on a network for running services?
  • What does a meta directory do?
  • What is a rainbow table used for in cybersecurity?
  • Which of the following is an example of a dynamic token?
  • What kind of access control is based on user identity and granted by an administrator?
  • What issue has Alex's company encountered due to his accumulated rights from previous roles?
  • What is an Access Control Matrix used for?
  • What type of technology is Jim implementing for his organization in a cloud identity solution?
  • What characterizes Attribute-based access control (ABAC)?
  • What is the primary advantage of using federated identity?
  • What is a consequence of having a very high false acceptance rate in a biometric system?
  • Which aspect is critical when selecting vulnerability scanning tools?
  • What is the main role of scripting in authentication systems?
  • Which of the following is NOT a benefit of using Kerberos?
  • Who ultimately decides access permissions in a Discretionary Access Control (DAC) system?
  • What type of LDAP services has Alex configured when using ports 636 and 3269?
  • Which access control model allows users to have more granular permissions based on system resources?
  • What is the most likely issue Susan faces if her Kerberos tickets are not accepted, given her setup is properly configured?
  • Which access control method grants permissions based on the identity of the user?
  • Which access control principle focuses on granting users minimal levels of access?
  • What type of attack is most likely to succeed against hashed passwords recovered during a penetration test?
  • What is the result of implementing Single Sign-On (SSO) for users?
  • What distinguishes a physical access control system from logical access control systems?
  • What is a critical requirement for the effective operation of Kerberos?
  • What type of attack focuses on exploiting weaknesses in the implementation of a cryptography system?
  • What type of token-based authentication system uses a challenge/response process?
  • What is the main focus of an implementation attack?
  • What should Alex implement to prevent eavesdropping on SAML traffic and ensure authenticity?
  • Which of the following is not a type of attack used against access controls?
  • What is the main purpose of authentication in identity management?
  • What is the term for the unauthorized interception and use of passwords?
  • Which of the following verifies identity based on possession?
  • What is a primary benefit of using electronic authentication?
  • Which access control concept best describes the ability to access information based on a user's specific needs?
  • Which biometric identification method is usually the most expensive to implement?
  • What is a disadvantage of the Kerberos system?
  • Which identity management method involves creating and managing users in a cloud environment?
  • In an access control model, what does 'RBAC' stand for?
  • Which term describes controls that establish or enforce a specific action or behavior?
  • What is the characteristic of a MAC address?
  • Which of the following best defines the principle of least privilege?
  • Which of the following describes a logical access control system?
  • Which of the following is best described as an access control model that focuses on subjects and identifies the object that each subject can access?
  • What does Lattice-Based Access Control rely on for authorization?
  • In which scenario would vulnerability scanning be considered essential?
  • What major issue often results from decentralized access control?
  • What principle ensures that access to an object is denied unless it has been explicitly granted?
  • What is a key advantage of using Nmap for scanning systems?
  • Which identity management method allows for single sign-on (SSO) through the handling of login requests by an on-premises identity provider?
  • Facial scans evaluate which of the following characteristics?
  • What risk is associated with allowing the OpenID relying party to control the connection to the OpenID provider?
  • Which Type 3 authenticator can be used on its own rather than in combination with other biometric factors?
  • What are access control systems designed to do?
  • In the relationship between identity, authentication, and authorization, what does identification provide?
  • Which of the following contributes to the administrative overhead of using Kerberos?
  • Which protocol is primarily used for handling XML-based messaging?
  • Which authentication method uses a nonce sent by the server to generate a one-time password?
  • What defines a one-time password?
  • What solution can help address concerns about third parties controlling single sign-on (SSO) directions?
  • What do file directories and devices represent in access control models?
  • What does Kerberos primarily address in its security framework?
  • Which tool is not typically used to verify adherence to a provisioning process that complies with security policy?
  • Why is it critical to monitor the resources a user is authorized to access?
  • What does Signature Dynamics capture when a person writes a signature?
  • In the context of network security, what is a significant advantage of Multi-factor Authentication?
  • How does the system use access control tokens?
  • What authentication factor would be classified as "something you have"?
  • Microsoft's Active Directory Domain Services is primarily based on which technology?
  • What should Ben do if the FAR and FRR in his biometric system do not meet acceptable performance levels?
  • What does accountability refer to in the context of identity management?
  • Which method is often the first type of network reconnaissance performed against a targeted network?
  • What type of access control limits login capabilities to work hours only, as configured in Susan's workstation?
  • What term describes the administrative domain for authentication in Kerberos?
  • What is the Crossover Error Rate (CER)?
  • Which access control model is typically non-discretionary in nature?
  • Why are salts used with hashes in password storage?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy