CIAM-IAM Implementation Considerations Flashcards

1
Q

The AAA identity and access management model is a framework which is embedded into the digital identity and access management world to manage access to assets and maintain system security. AAA stands for A__________, A__________, and A__________.

A

AAA stands for Authentication, Authorization, and Accounting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

4 Primary types of authentication methods

A
  1. Static passwords which remain active until they are changed or expired
  2. One-time password (OTP) such as codes delivered thorough SMS texts or tokens used for each access session
  3. Digital certificate
  4. Biometric credential
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Multi-Factor Authentication (MFA)

A

It is combining more than one of these categories

  1. Something you know such has a password
  2. Something you have such as a key fob or cell phone; and
  3. Something you are such as your finger prints, voice, hand geometry, etc also called “biometrics authentications.”
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Any authorization beyond normal job functions opens the door for either accidental or malicious violations of security objectives; CIA

A

Confidentiality, Integrity, and Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The Principle of Least Privilege requires that users, processes, programs, and devices must only be granted…

A

…sufficient access necessary to perform their required functions, and nothing more

The principle of least privilege must be applied at all times until it is time to temporarily escalate access when warranted by business requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In order to be effective in IAM accounting, generic and shared accounts must be

A

avoided so that the actions of each individual can be accounted for

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The Principle of Least Privilege

A

The principle of least privilege applies to Authorization in the AAA identity and access management model.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly