ISC2 CISSP Federation And Authorization Models Practice Test
5 Identity and Access Management (IAM) • 26 original questions
This CISSP practice test focuses on federation and authorization models through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
City Power is standardizing security across several business units. The customer identity platform raises a question about Policy decision and policy enforcement points. The security governance lead needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The identity population includes 4,700 workforce, service, or device identities.
Correct answer: D
Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.
Option review:
A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.
D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.
Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.
During a internal audit response, Tailspin Logistics asks the IAM architect to address On-premises federation for its data analytics lake. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The identity population includes 6,400 workforce, service, or device identities.
Correct answer: C
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.
D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
Alpine Sports is revising controls for its branch-office network. A review highlights Cloud federation. The application security architect must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The identity population includes 8,100 workforce, service, or device identities.
Correct answer: D
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
An auditor asks Fabrikam Manufacturing to demonstrate how it handles Hybrid federation in the industrial control network. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The identity population includes 700 workforce, service, or device identities.
Correct answer: D
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
After a business change, Trey Research discovers that Role-based access control (RBAC) is not handled consistently for the research data repository. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The identity population includes 2,400 workforce, service, or device identities.
Correct answer: D
Why: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
D: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.
Learning point: Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation. RBAC scales access through business roles when role membership accurately reflects job responsibilities.
Margie Travel is preparing a security decision for the payment processing service. The decision involves Rule-based access control. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The identity population includes 4,100 workforce, service, or device identities.
Correct answer: B
Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.
During a risk workshop for the software delivery pipeline, the team identifies Mandatory access control (MAC) as the deciding issue. The application security architect is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The identity population includes 5,800 workforce, service, or device identities.
Correct answer: A
Why: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.
Option review:
A: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
Learning point: Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy. MAC is appropriate for centrally controlled label-based policy with little user discretion.
A control owner at Bellows University proposes a quick technical fix for On-premises federation in the AI-assisted customer service platform. The incident response manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The identity population includes 7,500 workforce, service, or device identities.
Correct answer: A
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation without granting broader privilege than the business need requires.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation without granting broader privilege than the business need requires.
B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
Litware Services is standardizing security across several business units. The global collaboration platform raises a question about Cloud federation. The security governance lead needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The identity population includes 9,200 workforce, service, or device identities.
Correct answer: A
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation without creating a new single point of failure.
Option review:
A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation without creating a new single point of failure.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
During a identity modernization project, Humongous Insurance asks the IAM architect to address Hybrid federation for its e-commerce application. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The identity population includes 1,800 workforce, service, or device identities.
Correct answer: D
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation while ensuring that emergency access cannot become permanent access.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation while ensuring that emergency access cannot become permanent access.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
Woodgrove Bank is revising controls for its clinical records environment. A review highlights Role-based access control (RBAC). The application security architect must address the control objective while allowing independent verification of the control outcome. Which action is the BEST next step? The identity population includes 3,500 workforce, service, or device identities.
Correct answer: D
Why: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while allowing independent verification of the control outcome.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
D: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while allowing independent verification of the control outcome.
Learning point: Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation. RBAC scales access through business roles when role membership accurately reflects job responsibilities.
An auditor asks Relecloud Systems to demonstrate how it handles Rule-based access control in the remote access service. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. Which response is MOST appropriate? The identity population includes 5,200 workforce, service, or device identities.
Correct answer: A
Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while accounting for third-party and lifecycle dependencies.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while accounting for third-party and lifecycle dependencies.
B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.
After a business change, Contoso Financial discovers that Mandatory access control (MAC) is not handled consistently for the customer identity platform. The security governance lead needs to address the control objective while maintaining the organization’s stated risk appetite. Which recommendation BEST addresses the issue? The identity population includes 6,900 workforce, service, or device identities.
Correct answer: C
Why: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while maintaining the organization’s stated risk appetite.
Option review:
A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
C: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while maintaining the organization’s stated risk appetite.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
Learning point: Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy. MAC is appropriate for centrally controlled label-based policy with little user discretion.
Lucerne Publishing is preparing a security decision for the data analytics lake. The decision involves Discretionary access control (DAC). The IAM architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which option BEST reflects CISSP-level security practice? The identity population includes 8,600 workforce, service, or device identities.
Correct answer: D
Why: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.
D: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) while meeting the business objective with the least unnecessary operational complexity.
Learning point: Use DAC when the resource owner is intentionally allowed to grant or revoke access within policy. DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC.
During a risk workshop for the branch-office network, the team identifies Attribute-based access control (ABAC) as the deciding issue. The application security architect is expected to address the control objective while keeping the control sustainable for normal operations. What is the MOST appropriate course of action? The identity population includes 1,200 workforce, service, or device identities.
Correct answer: A
Why: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) while keeping the control sustainable for normal operations.
Option review:
A: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) while keeping the control sustainable for normal operations.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.
D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.
Learning point: Use ABAC when decisions must combine user, resource, action, and environmental attributes dynamically. ABAC supports fine-grained context-aware policy beyond static roles.
A control owner at Fourth Coffee proposes a quick technical fix for Risk-based access control in the industrial control network. The incident response manager must address the control objective while ensuring the decision can be repeated consistently across business units. What should happen FIRST? The identity population includes 2,900 workforce, service, or device identities.
Correct answer: A
Why: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring the decision can be repeated consistently across business units.
Option review:
A: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring the decision can be repeated consistently across business units.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.
Learning point: Use risk-based access when the decision must adapt to signals such as device health, location, behavior, or transaction risk. Risk-based access changes assurance requirements according to contextual risk.
Consolidated Messenger is standardizing security across several business units. The research data repository raises a question about Policy decision and policy enforcement points. The security governance lead needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The identity population includes 4,600 workforce, service, or device identities.
Correct answer: A
Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.
Option review:
A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Policy decision and policy enforcement points while preserving clear accountability and audit evidence.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.
D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Policy decision and policy enforcement points in this scenario.
Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.
During a architecture design review, Proseware Labs asks the IAM architect to address On-premises federation for its payment processing service. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The identity population includes 6,300 workforce, service, or device identities.
Correct answer: C
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses On-premises federation while protecting sensitive data throughout the change.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address On-premises federation in this scenario.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
Southridge Media is revising controls for its software delivery pipeline. A review highlights Cloud federation. The application security architect must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The identity population includes 8,000 workforce, service, or device identities.
Correct answer: D
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Cloud federation in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Cloud federation while preserving availability of the critical business service.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
An auditor asks Adventure Works to demonstrate how it handles Hybrid federation in the AI-assisted customer service platform. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The identity population includes 600 workforce, service, or device identities.
Correct answer: C
Why: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.
Option review:
A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. It directly addresses Hybrid federation without replacing governance with a technology-only shortcut.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Hybrid federation in this scenario.
Learning point: Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle. Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated.
After a business change, VanArsdel Energy discovers that Role-based access control (RBAC) is not handled consistently for the global collaboration platform. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The identity population includes 2,300 workforce, service, or device identities.
Correct answer: C
Why: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
C: RBAC scales access through business roles when role membership accurately reflects job responsibilities. It directly addresses Role-based access control (RBAC) while keeping the process defensible to auditors and business owners.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Role-based access control (RBAC) in this scenario.
Learning point: Use RBAC when stable job functions are the primary basis for access and manage role design to avoid privilege accumulation. RBAC scales access through business roles when role membership accurately reflects job responsibilities.
Northwind Health is preparing a security decision for the e-commerce application. The decision involves Rule-based access control. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The identity population includes 4,000 workforce, service, or device identities.
Correct answer: C
Why: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.
Option review:
A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. It directly addresses Rule-based access control while minimizing irreversible action until facts and authority are established.
D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Rule-based access control in this scenario.
Learning point: Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture. RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems.
During a risk workshop for the clinical records environment, the team identifies Mandatory access control (MAC) as the deciding issue. The application security architect is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The identity population includes 5,700 workforce, service, or device identities.
Correct answer: C
Why: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
C: MAC is appropriate for centrally controlled label-based policy with little user discretion. It directly addresses Mandatory access control (MAC) while preserving evidence needed for later review.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Mandatory access control (MAC) in this scenario.
Learning point: Use MAC when centrally enforced labels and clearances must prevent users or owners from overriding policy. MAC is appropriate for centrally controlled label-based policy with little user discretion.
A control owner at A. Datum Analytics proposes a quick technical fix for Discretionary access control (DAC) in the remote access service. The incident response manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The identity population includes 7,400 workforce, service, or device identities.
Correct answer: B
Why: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) without granting broader privilege than the business need requires.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.
B: DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC. It directly addresses Discretionary access control (DAC) without granting broader privilege than the business need requires.
C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.
D: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Discretionary access control (DAC) in this scenario.
Learning point: Use DAC when the resource owner is intentionally allowed to grant or revoke access within policy. DAC delegates access decisions to resource owners and therefore offers less centralized control than MAC.
Blue Yonder Airlines is standardizing security across several business units. The customer identity platform raises a question about Attribute-based access control (ABAC). The security governance lead needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The identity population includes 9,100 workforce, service, or device identities.
Correct answer: D
Why: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) without creating a new single point of failure.
Option review:
A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.
B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Attribute-based access control (ABAC) in this scenario.
D: ABAC supports fine-grained context-aware policy beyond static roles. It directly addresses Attribute-based access control (ABAC) without creating a new single point of failure.
Learning point: Use ABAC when decisions must combine user, resource, action, and environmental attributes dynamically. ABAC supports fine-grained context-aware policy beyond static roles.
During a internal audit response, City Power asks the IAM architect to address Risk-based access control for its data analytics lake. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The identity population includes 1,700 workforce, service, or device identities.
Correct answer: A
Why: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring that emergency access cannot become permanent access.
Option review:
A: Risk-based access changes assurance requirements according to contextual risk. It directly addresses Risk-based access control while ensuring that emergency access cannot become permanent access.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.
C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.
D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Risk-based access control in this scenario.
Learning point: Use risk-based access when the decision must adapt to signals such as device health, location, behavior, or transaction risk. Risk-based access changes assurance requirements according to contextual risk.
Popular posts
Recent Posts
