ISC2 CISSP Federation And Authorization Models Practice Test

 

5 Identity and Access Management (IAM) • 26 original questions

This CISSP practice test focuses on federation and authorization models through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

City Power is standardizing security across several business units. The customer identity platform raises a question about Policy decision and policy enforcement points. The security governance lead needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The identity population includes 4,700 workforce, service, or device identities.

  1. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: D

Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.

Option review:

A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.

Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.

Question 2

During a internal audit response, Tailspin Logistics asks the IAM architect to address On-premises federation for its data analytics lake. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The identity population includes 6,400 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.

Correct answer: C

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.

D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 3

Alpine Sports is revising controls for its branch-office network. A review highlights Cloud federation. The application security architect must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The identity population includes 8,100 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: D

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 4

An auditor asks Fabrikam Manufacturing to demonstrate how it handles Hybrid federation in the industrial control network. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The identity population includes 700 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: D

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 5

After a business change, Trey Research discovers that Role-based access control (RBAC) is not handled consistently for the research data repository. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The identity population includes 2,400 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation.

Correct answer: D

Why: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

D: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.

Learning point: Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation. RBAC scales access through business roles when role membership accurately reflects job responsibilities.

Question 6

Margie Travel is preparing a security decision for the payment processing service. The decision involves Rule-based access control. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The identity population includes 4,100 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: B

Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.

Question 7

During a risk workshop for the software delivery pipeline, the team identifies Mandatory access control (MAC) as the deciding issue. The application security architect is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The identity population includes 5,800 workforce, service, or device identities.

  1. Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: A

Why: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.

Option review:

A: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

Learning point: Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy. MAC is appropriate for centrally controlled label-based policy with little user discretion.

Question 8

A control owner at Bellows University proposes a quick technical fix for On-premises federation in the AI-assisted customer service platform. The incident response manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The identity population includes 7,500 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: A

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation without granting broader privilege than the business need requires.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation without granting broader privilege than the business need requires.

B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 9

Litware Services is standardizing security across several business units. The global collaboration platform raises a question about Cloud federation. The security governance lead needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The identity population includes 9,200 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: A

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation without creating a new single point of failure.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation without creating a new single point of failure.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 10

During a identity modernization project, Humongous Insurance asks the IAM architect to address Hybrid federation for its e-commerce application. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The identity population includes 1,800 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: D

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation while ensuring that emergency access cannot become permanent access.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 11

Woodgrove Bank is revising controls for its clinical records environment. A review highlights Role-based access control (RBAC). The application security architect must address the control objective while allowing independent verification of the control outcome. Which action is the BEST next step? The identity population includes 3,500 workforce, service, or device identities.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation.

Correct answer: D

Why: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while allowing independent verification of the control outcome.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

D: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while allowing independent verification of the control outcome.

Learning point: Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation. RBAC scales access through business roles when role membership accurately reflects job responsibilities.

Question 12

An auditor asks Relecloud Systems to demonstrate how it handles Rule-based access control in the remote access service. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. Which response is MOST appropriate? The identity population includes 5,200 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: A

Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while accounting for third-party and lifecycle dependencies.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while accounting for third-party and lifecycle dependencies.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.

Question 13

After a business change, Contoso Financial discovers that Mandatory access control (MAC) is not handled consistently for the customer identity platform. The security governance lead needs to address the control objective while maintaining the organization’s stated risk appetite. Which recommendation BEST addresses the issue? The identity population includes 6,900 workforce, service, or device identities.

  1. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while maintaining the organization’s stated risk appetite.

Option review:

A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

C: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while maintaining the organization’s stated risk appetite.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

Learning point: Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy. MAC is appropriate for centrally controlled label-based policy with little user discretion.

Question 14

Lucerne Publishing is preparing a security decision for the data analytics lake. The decision involves Discretionary access control (DAC). The IAM architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which option BEST reflects CISSP-level security practice? The identity population includes 8,600 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Use DAC when the resource owner is intentionally allowed to grant or revoke access within policy.

Correct answer: D

Why: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.

D: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) while meeting the business objective with the least unnecessary operational complexity.

Learning point: Use DAC when the resource owner is intentionally allowed to grant or revoke access within policy. DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC.

Question 15

During a risk workshop for the branch-office network, the team identifies Attribute-based access control (ABAC) as the deciding issue. The application security architect is expected to address the control objective while keeping the control sustainable for normal operations. What is the MOST appropriate course of action? The identity population includes 1,200 workforce, service, or device identities.

  1. Use ABAC when decisions must combine user, resource, action, and environmental attributes dynamically.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: A

Why: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) while keeping the control sustainable for normal operations.

Option review:

A: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) while keeping the control sustainable for normal operations.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.

Learning point: Use ABAC when decisions must combine user, resource, action, and environmental attributes dynamically. ABAC supports fine-grained context-aware policy beyond static roles.

Question 16

A control owner at Fourth Coffee proposes a quick technical fix for Risk-based access control in the industrial control network. The incident response manager must address the control objective while ensuring the decision can be repeated consistently across business units. What should happen FIRST? The identity population includes 2,900 workforce, service, or device identities.

  1. Use risk-based access when the decision must adapt to signals such as device health, location, behavior, or transaction risk.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring the decision can be repeated consistently across business units.

Option review:

A: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring the decision can be repeated consistently across business units.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.

Learning point: Use risk-based access when the decision must adapt to signals such as device health, location, behavior, or transaction risk. Risk-based access changes assurance requirements according to contextual risk.

Question 17

Consolidated Messenger is standardizing security across several business units. The research data repository raises a question about Policy decision and policy enforcement points. The security governance lead needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The identity population includes 4,600 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: A

Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.

Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.

Question 18

During a architecture design review, Proseware Labs asks the IAM architect to address On-premises federation for its payment processing service. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The identity population includes 6,300 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: C

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 19

Southridge Media is revising controls for its software delivery pipeline. A review highlights Cloud federation. The application security architect must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The identity population includes 8,000 workforce, service, or device identities.

  1. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: D

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.

Option review:

A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 20

An auditor asks Adventure Works to demonstrate how it handles Hybrid federation in the AI-assisted customer service platform. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The identity population includes 600 workforce, service, or device identities.

  1. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: C

Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.

Option review:

A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.

Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.

Question 21

After a business change, VanArsdel Energy discovers that Role-based access control (RBAC) is not handled consistently for the global collaboration platform. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The identity population includes 2,300 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

C: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.

Learning point: Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation. RBAC scales access through business roles when role membership accurately reflects job responsibilities.

Question 22

Northwind Health is preparing a security decision for the e-commerce application. The decision involves Rule-based access control. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The identity population includes 4,000 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: C

Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.

Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.

Question 23

During a risk workshop for the clinical records environment, the team identifies Mandatory access control (MAC) as the deciding issue. The application security architect is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The identity population includes 5,700 workforce, service, or device identities.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: C

Why: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

C: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.

Learning point: Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy. MAC is appropriate for centrally controlled label-based policy with little user discretion.

Question 24

A control owner at A. Datum Analytics proposes a quick technical fix for Discretionary access control (DAC) in the remote access service. The incident response manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The identity population includes 7,400 workforce, service, or device identities.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Use DAC when the resource owner is intentionally allowed to grant or revoke access within policy.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.

Correct answer: B

Why: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) without granting broader privilege than the business need requires.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.

B: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) without granting broader privilege than the business need requires.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.

D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.

Learning point: Use DAC when the resource owner is intentionally allowed to grant or revoke access within policy. DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC.

Question 25

Blue Yonder Airlines is standardizing security across several business units. The customer identity platform raises a question about Attribute-based access control (ABAC). The security governance lead needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The identity population includes 9,100 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Use ABAC when decisions must combine user, resource, action, and environmental attributes dynamically.

Correct answer: D

Why: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) without creating a new single point of failure.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.

D: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) without creating a new single point of failure.

Learning point: Use ABAC when decisions must combine user, resource, action, and environmental attributes dynamically. ABAC supports fine-grained context-aware policy beyond static roles.

Question 26

During a internal audit response, City Power asks the IAM architect to address Risk-based access control for its data analytics lake. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The identity population includes 1,700 workforce, service, or device identities.

  1. Use risk-based access when the decision must adapt to signals such as device health, location, behavior, or transaction risk.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: A

Why: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring that emergency access cannot become permanent access.

Option review:

A: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring that emergency access cannot become permanent access.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.

Learning point: Use risk-based access when the decision must adapt to signals such as device health, location, behavior, or transaction risk. Risk-based access changes assurance requirements according to contextual risk.

Popular posts

img