IAM Flashcards

1
Q

What are the core concepts of IAM

A

Identity management
Authentication
Authorisation
Access management
Governance and compliance
Monitoring and intelligence
Life cycle management

It’s crucial for securing the organisation’s resources and implementing least privilege access. Helps protect sensitive information, streamline user access and enhance overall security posture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain identity management

A

Creation, maintenance and deletion of accounts, each user or app has a unique identity, which can self serve for profile updates and password resets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is authentication

A

Verifying the identity of users, devices or systems. Verifying that a party is who they say they are. Includes MFA, SSO, biometrics, certificates etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is authorisation

A

Determines what a user is allowed to do. RBAC and ABAC (attribute) and policy based control mechanisms. Conditional access for example.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is access management

A

Ensuring users have access to appropriate resources. Should be able to request access using workflow/automation. PIM controls privileged access, is a form of PAM.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Governance and compliance

A

Adhering to regulatory requirements, internal policies and industry standards. Auditing, reporting, policy management, and risk management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are monitoring and intelligence

A

Involve continuously analysing user activities to detect and respond to anomalies and security threats.

In Entra ID examples are Identity protection, built in logs that can be sent to SIEM or SOAR for correlation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is lifecycle management.

A

Covers the entire identity lifecycle, initial provisioning and de-provisioning/account cleanup. Includes lifecycle events, department moves, promotions, long term absence etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Entra identity governance

A

Additional licence
Inbound, outbound and sync provisioning
Identity lifecycles
Entitlement management
PIM
Access reviews

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Entra identity governance

A

Additional licence
Inbound, outbound and sync provisioning
Identity lifecycles
Entitlement management
PIM
Access reviews

How well did you know this?
1
Not at all
2
3
4
5
Perfectly