Identity and Access Management (IAM)
CISSP · 39 questions
- A county court hosts sealed juvenile records that must stay available only to authorized staff. Which access approach correctly addresses both information and systems?
- Badge readers on the police evidence room unlock automatically when power fails. What facility access design principle should the security architect enforce?
- A city’s public snowplow-location API accidentally shares the same exposure path as internal fleet-admin services. What access-control boundary should be applied?
- A municipality protects both a data-center cage and a public library self-checkout kiosk. How should access-control strength be applied?
- An auditor finds a stolen city badge can be paired with passwords written on sticky notes at workstations. What lesson about combined physical and logical controls applies?
- A county clerk’s office grants application rights user-by-user instead of by job function for clerks versus auditors. Which identity strategy should replace that practice?
- Finance staff reach the treasury network over VPN using passwords alone. Which authentication strategy change is most appropriate?
- Library staff leave authenticated sessions open on shared public-service PCs between patrons. What session-management control should be required for sensitive apps?
- Remote contractors receive municipal accounts from an emailed spreadsheet with no identity proofing. What registration practice should replace that process?
- County applications currently force unique passwords everywhere, while a trusted state identity provider already authenticates the same employees. Which approach applies federated identity management?
- Shared service-account passwords for city integrations are stored in a wiki editable by dozens of staff. What credential-management change is required?
- Residents must maintain twenty separate logins for related city services. How should single sign-on be applied?
- Fire-department IT admins hold standing domain privileges for tasks they perform only a few times a year. Which authorization design reduces that risk?
- Legacy on-premises mutual-aid applications must accept identities from a partner agency’s identity provider. Which design best secures that on-prem federation?
- A SaaS HR platform will authenticate city employees via the city’s identity provider. What must the architect manage for cloud federation?
- Some municipal apps remain on-premises while others are SaaS, yet leadership wants one coherent identity strategy. Which approach fits hybrid federation?
- Federation to a low-assurance partner app currently releases full Social Security numbers with every login. What trust-boundary fix is required?
- A firefighter separates from the department but still can open mutual-aid apps through federation. What lifecycle control is missing?
- A building-permit system needs permissions that match clerk job duties rather than one-off exceptions. Which authorization model should be implemented?
- A city fusion center stores highly sensitive investigative files under system-enforced classification labels, while a parks department team drive lets folder owners decide who can share documents. Which access-control contrast best describes these two approaches?
- A municipal ERP portal must allow finance staff access only during published business hours and only from city office subnets. Which authorization approach best matches that design?
- Mobile health inspectors need access to case records only when their clearance is sufficient, they are within an assigned district geofence, and the request occurs during their shift. Which model best expresses that decision?
- A county employee account attempts to sign in at 03:00 from a country the worker has never visited. What access-control response best reflects a risk-based decision?
- A city zero-trust design uses a central policy engine to evaluate access requests while API gateways and VPN concentrators only allow or deny based on that decision. Which roles do those components play?
- A library catalog system holds only public bibliographic data and needs simple staff roles, while a police evidence vault needs label-enforced separation. What should the CISO emphasize when choosing authorization models?
- A quarterly IAM review for a city internship program finds dozens of dormant accounts that still have portal access months after interns left. What control practice does this finding primarily reinforce?
- A permitting clerk transfers to the assessor's office but retains write access to the old permitting workflow for six months. Which IAM lifecycle gap is most evident?
- A utility billing clerk is promoted to supervisor. Leadership wants the new role approvals without keeping every former clerk entitlement. What is the soundest approach?
- Server admins on the city virtualization cluster use uncontrolled sudo and local admin elevation with little logging. What should governance require first?
- An audit finds batch-job service accounts for the water billing system with non-expiring passwords and interactive logon rights on jump hosts. Which remediation best hardens those accounts?
- A smart-city pilot ends, yet project AD groups and API keys still grant access to IoT dashboards. What should IAM operations prioritize?
- HR ticket-only provisioning for a large city workforce causes multi-day delays and frequent wrong-role assignments. Which improvement best addresses reliability while retaining governance?
- A municipality is modernizing identity: a central directory, MFA for remote access, and federation to cloud SaaS used by multiple departments. What implementation priority best keeps those pieces coherent?
- Help-desk phishing calls successfully harvest SMS one-time passcodes from city employees. Which authentication direction best reduces that risk where feasible?
- Remote staff authenticate with MFA, yet unmanaged personal laptops freely reach the tax-system VPN. What gap should the access design close?
- A 311 mobile app embeds long-lived static API keys that call backend microservices. Which change best improves service-to-service authentication?
- Emergency break-glass admin accounts for the city identity platform are used weekly for routine changes and generate no alerts. What redesign is most appropriate?
- SIEM dashboards show repeated failed logons and impossible-travel alerts for municipal SSO, but the identity team never tunes or responds to them. What practice is missing?
- Several legacy line-of-business apps still require NTLM-only authentication and thereby block MFA enforcement for those pathways. What should the security program prioritize?