ISC2 CISSP Identity Proofing Authentication MFA SSO And Session Security Practice Test
5 Identity and Access Management (IAM) • 26 original questions
This CISSP practice test focuses on identity proofing authentication mfa sso and session security through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a risk workshop for the AI-assisted customer service platform, the team identifies Single sign-on (SSO) as the deciding issue. The enterprise security engineer is expected to address the control objective while accounting for third-party and lifecycle dependencies. What is the MOST appropriate course of action? The identity population includes 3,600 workforce, service, or device identities.
Correct answer: B
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Single sign-on (SSO) while accounting for third-party and lifecycle dependencies.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Single sign-on (SSO) in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Single sign-on (SSO) while accounting for third-party and lifecycle dependencies.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Single sign-on (SSO) in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Single sign-on (SSO) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
A control owner at Lamna Healthcare proposes a quick technical fix for Just-In-Time access in the global collaboration platform. The chief information security officer must address the control objective while maintaining the organization’s stated risk appetite. What should happen FIRST? The identity population includes 5,300 workforce, service, or device identities.
Correct answer: A
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Just-In-Time access while maintaining the organization’s stated risk appetite.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Just-In-Time access while maintaining the organization’s stated risk appetite.
B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Just-In-Time access in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Just-In-Time access in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Just-In-Time access in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Fourth Coffee is standardizing security across several business units. The e-commerce application raises a question about Groups and roles. The risk manager needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action provides the BEST governance and security outcome? The identity population includes 7,000 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Groups and roles while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Groups and roles while meeting the business objective with the least unnecessary operational complexity.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
During a network segmentation redesign, Consolidated Messenger asks the security assurance manager to address Authentication, Authorization and Accounting (AAA) for its clinical records environment. The requirement is to address the control objective while keeping the control sustainable for normal operations. What should the organization do FIRST? The identity population includes 8,700 workforce, service, or device identities.
Correct answer: B
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Authentication, Authorization and Accounting (AAA) while keeping the control sustainable for normal operations.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Authentication, Authorization and Accounting (AAA) while keeping the control sustainable for normal operations.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Proseware Labs is revising controls for its remote access service. A review highlights Multi-factor authentication (MFA). The enterprise security engineer must address the control objective while ensuring the decision can be repeated consistently across business units. Which action is the BEST next step? The identity population includes 1,300 workforce, service, or device identities.
Correct answer: B
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Multi-factor authentication (MFA) while ensuring the decision can be repeated consistently across business units.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Multi-factor authentication (MFA) while ensuring the decision can be repeated consistently across business units.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
An auditor asks Southridge Media to demonstrate how it handles Passwordless authentication in the customer identity platform. The chief information security officer must address the control objective while preserving clear accountability and audit evidence. Which response is MOST appropriate? The identity population includes 3,000 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Passwordless authentication while preserving clear accountability and audit evidence.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Passwordless authentication while preserving clear accountability and audit evidence.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
After a business change, Adventure Works discovers that Session management is not handled consistently for the data analytics lake. The risk manager needs to address the control objective while protecting sensitive data throughout the change. Which recommendation BEST addresses the issue? The identity population includes 4,700 workforce, service, or device identities.
Correct answer: B
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Session management while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Session management while protecting sensitive data throughout the change.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
VanArsdel Energy is preparing a security decision for the branch-office network. The decision involves Registration, proofing, and establishment of identity. The security assurance manager must address the control objective while preserving availability of the critical business service. Which option BEST reflects CISSP-level security practice? The identity population includes 6,400 workforce, service, or device identities.
Correct answer: A
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Registration, proofing, and establishment of identity while preserving availability of the critical business service.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Registration, proofing, and establishment of identity while preserving availability of the critical business service.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
During a risk workshop for the industrial control network, the team identifies Groups and roles as the deciding issue. The enterprise security engineer is expected to address the control objective without replacing governance with a technology-only shortcut. What is the MOST appropriate course of action? The identity population includes 8,100 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Groups and roles without replacing governance with a technology-only shortcut.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Groups and roles without replacing governance with a technology-only shortcut.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
A control owner at Coho Insurance proposes a quick technical fix for Authentication, Authorization and Accounting (AAA) in the research data repository. The chief information security officer must address the control objective while keeping the process defensible to auditors and business owners. What should happen FIRST? The identity population includes 700 workforce, service, or device identities.
Correct answer: A
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Authentication, Authorization and Accounting (AAA) while keeping the process defensible to auditors and business owners.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Authentication, Authorization and Accounting (AAA) while keeping the process defensible to auditors and business owners.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Multi-factor authentication (MFA) while minimizing irreversible action until facts and authority are established.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Multi-factor authentication (MFA) while minimizing irreversible action until facts and authority are established.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
During a data-governance workshop, Blue Yonder Airlines asks the security assurance manager to address Passwordless authentication for its software delivery pipeline. The requirement is to address the control objective while preserving evidence needed for later review. What should the organization do FIRST? The identity population includes 4,100 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Passwordless authentication while preserving evidence needed for later review.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Passwordless authentication while preserving evidence needed for later review.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
City Power is revising controls for its AI-assisted customer service platform. A review highlights Session management. The enterprise security engineer must address the control objective without granting broader privilege than the business need requires. Which action is the BEST next step? The identity population includes 5,800 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Session management without granting broader privilege than the business need requires.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Session management without granting broader privilege than the business need requires.
D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
An auditor asks Tailspin Logistics to demonstrate how it handles Registration, proofing, and establishment of identity in the global collaboration platform. The chief information security officer must address the control objective without creating a new single point of failure. Which response is MOST appropriate? The identity population includes 7,500 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Registration, proofing, and establishment of identity without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Registration, proofing, and establishment of identity without creating a new single point of failure.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
After a business change, Alpine Sports discovers that Federated Identity Management (FIM) is not handled consistently for the e-commerce application. The risk manager needs to address the control objective while ensuring that emergency access cannot become permanent access. Which recommendation BEST addresses the issue? The identity population includes 9,200 workforce, service, or device identities.
Correct answer: A
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Federated Identity Management (FIM) while ensuring that emergency access cannot become permanent access.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Federated Identity Management (FIM) while ensuring that emergency access cannot become permanent access.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Federated Identity Management (FIM) in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Federated Identity Management (FIM) in this scenario.
D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Federated Identity Management (FIM) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Fabrikam Manufacturing is preparing a security decision for the clinical records environment. The decision involves Credential management and password vaults. The security assurance manager must address the control objective while allowing independent verification of the control outcome. Which option BEST reflects CISSP-level security practice? The identity population includes 1,800 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Credential management and password vaults while allowing independent verification of the control outcome.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Credential management and password vaults in this scenario.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Credential management and password vaults in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Credential management and password vaults while allowing independent verification of the control outcome.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Credential management and password vaults in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
During a risk workshop for the remote access service, the team identifies Single sign-on (SSO) as the deciding issue. The enterprise security engineer is expected to address the control objective while accounting for third-party and lifecycle dependencies. What is the MOST appropriate course of action? The identity population includes 3,500 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Single sign-on (SSO) while accounting for third-party and lifecycle dependencies.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Single sign-on (SSO) in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Single sign-on (SSO) in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Single sign-on (SSO) in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Single sign-on (SSO) while accounting for third-party and lifecycle dependencies.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
A control owner at Margie Travel proposes a quick technical fix for Just-In-Time access in the customer identity platform. The chief information security officer must address the control objective while maintaining the organization’s stated risk appetite. What should happen FIRST? The identity population includes 5,200 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Just-In-Time access while maintaining the organization’s stated risk appetite.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Just-In-Time access in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Just-In-Time access in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Just-In-Time access in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Just-In-Time access while maintaining the organization’s stated risk appetite.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Wide World Importers is standardizing security across several business units. The data analytics lake raises a question about Groups and roles. The risk manager needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action provides the BEST governance and security outcome? The identity population includes 6,900 workforce, service, or device identities.
Correct answer: B
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Groups and roles while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Groups and roles while meeting the business objective with the least unnecessary operational complexity.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Groups and roles in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
During a regulatory readiness assessment, Bellows University asks the security assurance manager to address Authentication, Authorization and Accounting (AAA) for its branch-office network. The requirement is to address the control objective while keeping the control sustainable for normal operations. What should the organization do FIRST? The identity population includes 8,600 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Authentication, Authorization and Accounting (AAA) while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Authentication, Authorization and Accounting (AAA) in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Authentication, Authorization and Accounting (AAA) while keeping the control sustainable for normal operations.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Litware Services is revising controls for its industrial control network. A review highlights Multi-factor authentication (MFA). The enterprise security engineer must address the control objective while ensuring the decision can be repeated consistently across business units. Which action is the BEST next step? The identity population includes 1,200 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Multi-factor authentication (MFA) while ensuring the decision can be repeated consistently across business units.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Multi-factor authentication (MFA) while ensuring the decision can be repeated consistently across business units.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Multi-factor authentication (MFA) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
An auditor asks Humongous Insurance to demonstrate how it handles Passwordless authentication in the research data repository. The chief information security officer must address the control objective while preserving clear accountability and audit evidence. Which response is MOST appropriate? The identity population includes 2,900 workforce, service, or device identities.
Correct answer: B
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Passwordless authentication while preserving clear accountability and audit evidence.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Passwordless authentication while preserving clear accountability and audit evidence.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Passwordless authentication in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
After a business change, Woodgrove Bank discovers that Session management is not handled consistently for the payment processing service. The risk manager needs to address the control objective while protecting sensitive data throughout the change. Which recommendation BEST addresses the issue? The identity population includes 4,600 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Session management while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Session management in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Session management while protecting sensitive data throughout the change.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Relecloud Systems is preparing a security decision for the software delivery pipeline. The decision involves Registration, proofing, and establishment of identity. The security assurance manager must address the control objective while preserving availability of the critical business service. Which option BEST reflects CISSP-level security practice? The identity population includes 6,300 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Registration, proofing, and establishment of identity while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Registration, proofing, and establishment of identity while preserving availability of the critical business service.
D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Registration, proofing, and establishment of identity in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
During a risk workshop for the AI-assisted customer service platform, the team identifies Federated Identity Management (FIM) as the deciding issue. The enterprise security engineer is expected to address the control objective without replacing governance with a technology-only shortcut. What is the MOST appropriate course of action? The identity population includes 8,000 workforce, service, or device identities.
Correct answer: C
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Federated Identity Management (FIM) without replacing governance with a technology-only shortcut.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Federated Identity Management (FIM) in this scenario.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Federated Identity Management (FIM) in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Federated Identity Management (FIM) without replacing governance with a technology-only shortcut.
D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Federated Identity Management (FIM) in this scenario.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
A control owner at Lucerne Publishing proposes a quick technical fix for Credential management and password vaults in the global collaboration platform. The chief information security officer must address the control objective while keeping the process defensible to auditors and business owners. What should happen FIRST? The identity population includes 600 workforce, service, or device identities.
Correct answer: D
Why: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Credential management and password vaults while keeping the process defensible to auditors and business owners.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Credential management and password vaults in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Credential management and password vaults in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Credential management and password vaults in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. It directly addresses Credential management and password vaults while keeping the process defensible to auditors and business owners.
Learning point: Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk. Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management.
Popular posts
Recent Posts
