TechNuggets Academy

Identity and Access Management (IAM)

Free ISC2 Certified Information Systems Security Professional (CISSP) practice — 6 questions on Identity and Access Management (IAM), with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Identity and Access Management (IAM)
A financial services company's Windows domain uses Kerberos for authentication. The security team discovers that an attacker compromised the krbtgt account hash and forged a Ticket Granting Ticket (TGT), allowing access to any resource in the domain while impersonating any user without ever contacting the KDC for validation. Which attack occurred, and what is the most effective remediation?
A golden ticket attack forges a TGT using the stolen krbtgt hash, granting the attacker domain-wide access as any user without further KDC validation. Because the krbtgt account has two active password versions (current and previous) used to validate tickets, the password must be reset twice, allowing replication in between, to fully invalidate all forged tickets.
Question 2 of 6 · Identity and Access Management (IAM)
A healthcare SaaS provider must allow users at partner hospitals to authenticate to the SaaS application using their own hospital's Active Directory credentials, with no copy of hospital credentials ever stored at the SaaS provider. Which identity architecture BEST satisfies this requirement?
Federated identity establishes a trust relationship between the hospital's IdP and the SaaS provider's SP, allowing the IdP to assert user identity via SAML without the SaaS provider ever storing or managing hospital credentials — the classic cross-organizational SSO pattern.
Question 3 of 6 · Identity and Access Management (IAM)
A network engineering team must authenticate administrators logging into routers and switches, and separately enforce granular command-level authorization — for example, permitting 'show' commands while denying 'configure terminal' access — as a distinct decision from authentication. Which AAA protocol should be implemented?
TACACS+ separates authentication, authorization, and accounting into three distinct processes and encrypts the entire packet payload, enabling granular per-command authorization decisions independent of the authentication step — the standard solution for network device administration with command-level control.
Question 4 of 6 · Identity and Access Management (IAM)
An organization must grant access to a cloud file repository based on a dynamic combination of the requesting user's department, time of day, device compliance posture, and geographic location, with the access decision re-evaluated at every request rather than fixed when the account was created. Which access control model should be implemented?
ABAC evaluates a policy engine against multiple subject, resource, and environmental attributes (department, time, device posture, location) at the moment of each access request, making it the only model among the options capable of dynamic, contextual, per-request evaluation.
Question 5 of 6 · Identity and Access Management (IAM)
During Kerberos authentication troubleshooting, users report intermittent login failures despite entering correct credentials. Investigation reveals the domain controller's clock and the client workstation's clock differ by 12 minutes. Which default Kerberos parameter explains this authentication failure?
Kerberos enforces a default maximum clock skew tolerance of 5 minutes as an anti-replay control; a 12-minute difference between client and KDC clocks exceeds this tolerance, causing the KDC to reject the authentication request even with valid credentials.
Question 6 of 6 · Identity and Access Management (IAM)
Which statement BEST differentiates just-in-time (JIT) access provisioning from traditional standing privileged access within an identity and access lifecycle management program?
JIT provisioning grants elevated privileges only for the duration needed to complete a specific task, with automatic expiration afterward, minimizing the attack surface of standing privileged accounts; standing access, by contrast, remains persistently assigned whether or not it is actively being used.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →