CIAP Certified Identity and Access Professional Exam Prep |
Complete Practice Questions & Detailed Rationales (2026/2027)
Question 1
What does the AAA framework stand for in information security and
identity management?
• A. Authentication, Authorization, and Accounting
• B. Access, Application, and Auditing
• C. Automation, Administration, and Attribution
• D. Assertion, Association, and Architecture
Correct Answer: A. Authentication, Authorization, and Accounting
Detailed Rationale: The AAA framework is the foundational security
model that verifies who a user is (Authentication), what they are
allowed to do (Authorization), and tracks their actions (Accounting).
Question 2
What is the fundamental difference between Identification and
Authentication?
• A. Identification claims an identity (e.g., username), whereas
authentication verifies that the identity claim is valid (e.g.,
password or biometric).
• B. Identification is performed by the cloud provider, while
authentication is performed locally.
, • C. Identification requires multi-factor authentication, whereas
authentication requires only a username.
• D. There is no operational difference between identification and
authentication.
Correct Answer: A. Identification claims an identity (e.g., username),
whereas authentication verifies that the identity claim is valid (e.g.,
password or biometric).
Detailed Rationale: You must first state who you are (identification)
before the system can prove that you are indeed who you claim to be
(authentication).
Question 3
What are the three primary traditional factors of authentication?
• A. Something you know, something you have, and something you
are.
• B. Something you write, something you think, and something you
encrypt.
• C. Somewhere you live, somewhere you work, and somewhere
you log in.
• D. Someone you trust, someone you verify, and someone you
audit.
Correct Answer: A. Something you know, something you have, and
something you are.
,Detailed Rationale: These three categories form the bedrock of
authentication credentials (e.g., passwords/PINs, tokens/smart cards,
and fingerprints/facial scans).
Question 4
What is Multi-Factor Authentication (MFA)?
• A. An authentication method that requires two or more distinct
credentials drawn from different authentication factors (e.g.,
something you know + something you have).
• B. Entering a password two times consecutively on the same login
screen.
• C. Using two different passwords created by the same user.
• D. Logging into two separate applications with a single username.
Correct Answer: A. An authentication method that requires two or
more distinct credentials drawn from different authentication factors
(e.g., something you know + something you have).
Detailed Rationale: MFA significantly hardens security because
compromising a single credential (like a password) is insufficient for an
attacker to gain access.
Question 5
What is Discretionary Access Control (DAC)?
• A. An access control model where the owner of a resource has full
discretion to determine and grant access permissions to other
users or groups.
, • B. An access control model dictated strictly by central security
administrators without user input.
• C. An automated model where access is granted based on user
clearance levels and data classification labels.
• D. An open access model where all users possess full read and
write access to all files.
Correct Answer: A. An access control model where the owner of a
resource has full discretion to determine and grant access permissions
to other users or groups.
Detailed Rationale: DAC models (commonly found in consumer
operating systems like Windows NTFS or Linux file permissions) place
control directly in the hands of the resource creator.
Question 6
What is Mandatory Access Control (MAC)?
• A. A non-discretionary access model where system-wide security
policies dictate access based on strict classification labels (e.g.,
Top Secret, Secret) and user clearance levels.
• B. A model where individual users can freely share files with
anyone in the company.
• C. A policy that mandates all employees use password managers.
• D. A cloud storage backup policy enforced by automated scripts.
Correct Answer: A. A non-discretionary access model where system-
wide security policies dictate access based on strict classification labels
(e.g., Top Secret, Secret) and user clearance levels.
Complete Practice Questions & Detailed Rationales (2026/2027)
Question 1
What does the AAA framework stand for in information security and
identity management?
• A. Authentication, Authorization, and Accounting
• B. Access, Application, and Auditing
• C. Automation, Administration, and Attribution
• D. Assertion, Association, and Architecture
Correct Answer: A. Authentication, Authorization, and Accounting
Detailed Rationale: The AAA framework is the foundational security
model that verifies who a user is (Authentication), what they are
allowed to do (Authorization), and tracks their actions (Accounting).
Question 2
What is the fundamental difference between Identification and
Authentication?
• A. Identification claims an identity (e.g., username), whereas
authentication verifies that the identity claim is valid (e.g.,
password or biometric).
• B. Identification is performed by the cloud provider, while
authentication is performed locally.
, • C. Identification requires multi-factor authentication, whereas
authentication requires only a username.
• D. There is no operational difference between identification and
authentication.
Correct Answer: A. Identification claims an identity (e.g., username),
whereas authentication verifies that the identity claim is valid (e.g.,
password or biometric).
Detailed Rationale: You must first state who you are (identification)
before the system can prove that you are indeed who you claim to be
(authentication).
Question 3
What are the three primary traditional factors of authentication?
• A. Something you know, something you have, and something you
are.
• B. Something you write, something you think, and something you
encrypt.
• C. Somewhere you live, somewhere you work, and somewhere
you log in.
• D. Someone you trust, someone you verify, and someone you
audit.
Correct Answer: A. Something you know, something you have, and
something you are.
,Detailed Rationale: These three categories form the bedrock of
authentication credentials (e.g., passwords/PINs, tokens/smart cards,
and fingerprints/facial scans).
Question 4
What is Multi-Factor Authentication (MFA)?
• A. An authentication method that requires two or more distinct
credentials drawn from different authentication factors (e.g.,
something you know + something you have).
• B. Entering a password two times consecutively on the same login
screen.
• C. Using two different passwords created by the same user.
• D. Logging into two separate applications with a single username.
Correct Answer: A. An authentication method that requires two or
more distinct credentials drawn from different authentication factors
(e.g., something you know + something you have).
Detailed Rationale: MFA significantly hardens security because
compromising a single credential (like a password) is insufficient for an
attacker to gain access.
Question 5
What is Discretionary Access Control (DAC)?
• A. An access control model where the owner of a resource has full
discretion to determine and grant access permissions to other
users or groups.
, • B. An access control model dictated strictly by central security
administrators without user input.
• C. An automated model where access is granted based on user
clearance levels and data classification labels.
• D. An open access model where all users possess full read and
write access to all files.
Correct Answer: A. An access control model where the owner of a
resource has full discretion to determine and grant access permissions
to other users or groups.
Detailed Rationale: DAC models (commonly found in consumer
operating systems like Windows NTFS or Linux file permissions) place
control directly in the hands of the resource creator.
Question 6
What is Mandatory Access Control (MAC)?
• A. A non-discretionary access model where system-wide security
policies dictate access based on strict classification labels (e.g.,
Top Secret, Secret) and user clearance levels.
• B. A model where individual users can freely share files with
anyone in the company.
• C. A policy that mandates all employees use password managers.
• D. A cloud storage backup policy enforced by automated scripts.
Correct Answer: A. A non-discretionary access model where system-
wide security policies dictate access based on strict classification labels
(e.g., Top Secret, Secret) and user clearance levels.