Certified Identity and Access Professional Exam |
Comprehensive IAM Practice Test & Detailed Explanations and
solutions
Question 1
What is the primary definition of Identity and Access Management
(IAM) in enterprise security?
• A. A framework of policies, processes, and technologies for
managing digital identities and controlling user access to critical
enterprise resources.
• B. A database tool for compiling monthly employee payroll sheets.
• C. A network protocol for routing packets across wide area
networks.
• D. A software utility for scanning computer hard drives for
malware.
Correct Answer: A. A framework of policies, processes, and
technologies for managing digital identities and controlling user access
to critical enterprise resources.
Detailed Rationale: IAM encompasses all foundational controls
ensuring that the right individuals access the right resources at the right
times for legitimate reasons.
Question 2
What constitutes a "Digital Identity" within an enterprise environment?
, • A. A unique representation of a subject (such as a user, service, or
device) characterized by a set of attributes and credentials within
a digital system.
• B. A physical passport or driver's license issued by government
authorities.
• C. A corporate email address signature block.
• D. A static IP address assigned to a workstation.
Correct Answer: A. A unique representation of a subject (such as a user,
service, or device) characterized by a set of attributes and credentials
within a digital system.
Detailed Rationale: Digital identities anchor security policies, linking
actions and permissions to specific identifiable entities across IT
architectures.
Question 3
What are the three core pillars comprising the AAA security framework?
• A. Authentication, Authorization, and Accounting.
• B. Analysis, Auditing, and Automation.
• C. Access, Administration, and Archiving.
• D. Application, Architecture, and Attestation.
Correct Answer: A. Authentication, Authorization, and Accounting.
Detailed Rationale: AAA provides the foundational triad for verifying
who a user is, what they are permitted to do, and tracking their activity
for auditing.
,Question 4
What is Authentication in the context of information security?
• A. The process of verifying the claimed identity of a user, service,
or device before granting system access.
• B. The process of determining what files a user can read or
modify.
• C. The logging of user login timestamps and session durations.
• D. The encryption of data stored in database tables.
Correct Answer: A. The process of verifying the claimed identity of a
user, service, or device before granting system access.
Detailed Rationale: Authentication answers the question "Who are
you?" by requiring proof of identity through credentials or tokens.
Question 5
What is Authorization in access control?
• A. The process of granting or denying specific permissions, rights,
and privileges to an authenticated identity based on predefined
security policies.
• B. The process of verifying a user's password during login.
• C. The generation of multi-factor authentication passcodes.
• D. The rotation of cryptographic keys on a schedule.
Correct Answer: A. The process of granting or denying specific
permissions, rights, and privileges to an authenticated identity based on
predefined security policies.
, Detailed Rationale: Authorization answers the question "What are you
allowed to do?" after authentication has successfully confirmed
identity.
Question 6
What is Accounting in the AAA security triad?
• A. The tracking, recording, and reporting of user activities,
resource consumption, and session histories for auditing and
accountability.
• B. The calculation of monthly financial statements and corporate
taxes.
• C. The counting of active directory user accounts.
• D. The measurement of network packet bandwidth utilization.
Correct Answer: A. The tracking, recording, and reporting of user
activities, resource consumption, and session histories for auditing and
accountability.
Detailed Rationale: Accounting provides non-repudiation and forensic
visibility by logging what authenticated users did and when they did it.
Question 7
What are the four primary factor categories used in authentication?
• A. Something you know, something you have, something you are,
and somewhere you are (or something you do).
• B. Username, password, email, and phone number.
• C. Hardware token, software token, SMS code, and push
notification.
Comprehensive IAM Practice Test & Detailed Explanations and
solutions
Question 1
What is the primary definition of Identity and Access Management
(IAM) in enterprise security?
• A. A framework of policies, processes, and technologies for
managing digital identities and controlling user access to critical
enterprise resources.
• B. A database tool for compiling monthly employee payroll sheets.
• C. A network protocol for routing packets across wide area
networks.
• D. A software utility for scanning computer hard drives for
malware.
Correct Answer: A. A framework of policies, processes, and
technologies for managing digital identities and controlling user access
to critical enterprise resources.
Detailed Rationale: IAM encompasses all foundational controls
ensuring that the right individuals access the right resources at the right
times for legitimate reasons.
Question 2
What constitutes a "Digital Identity" within an enterprise environment?
, • A. A unique representation of a subject (such as a user, service, or
device) characterized by a set of attributes and credentials within
a digital system.
• B. A physical passport or driver's license issued by government
authorities.
• C. A corporate email address signature block.
• D. A static IP address assigned to a workstation.
Correct Answer: A. A unique representation of a subject (such as a user,
service, or device) characterized by a set of attributes and credentials
within a digital system.
Detailed Rationale: Digital identities anchor security policies, linking
actions and permissions to specific identifiable entities across IT
architectures.
Question 3
What are the three core pillars comprising the AAA security framework?
• A. Authentication, Authorization, and Accounting.
• B. Analysis, Auditing, and Automation.
• C. Access, Administration, and Archiving.
• D. Application, Architecture, and Attestation.
Correct Answer: A. Authentication, Authorization, and Accounting.
Detailed Rationale: AAA provides the foundational triad for verifying
who a user is, what they are permitted to do, and tracking their activity
for auditing.
,Question 4
What is Authentication in the context of information security?
• A. The process of verifying the claimed identity of a user, service,
or device before granting system access.
• B. The process of determining what files a user can read or
modify.
• C. The logging of user login timestamps and session durations.
• D. The encryption of data stored in database tables.
Correct Answer: A. The process of verifying the claimed identity of a
user, service, or device before granting system access.
Detailed Rationale: Authentication answers the question "Who are
you?" by requiring proof of identity through credentials or tokens.
Question 5
What is Authorization in access control?
• A. The process of granting or denying specific permissions, rights,
and privileges to an authenticated identity based on predefined
security policies.
• B. The process of verifying a user's password during login.
• C. The generation of multi-factor authentication passcodes.
• D. The rotation of cryptographic keys on a schedule.
Correct Answer: A. The process of granting or denying specific
permissions, rights, and privileges to an authenticated identity based on
predefined security policies.
, Detailed Rationale: Authorization answers the question "What are you
allowed to do?" after authentication has successfully confirmed
identity.
Question 6
What is Accounting in the AAA security triad?
• A. The tracking, recording, and reporting of user activities,
resource consumption, and session histories for auditing and
accountability.
• B. The calculation of monthly financial statements and corporate
taxes.
• C. The counting of active directory user accounts.
• D. The measurement of network packet bandwidth utilization.
Correct Answer: A. The tracking, recording, and reporting of user
activities, resource consumption, and session histories for auditing and
accountability.
Detailed Rationale: Accounting provides non-repudiation and forensic
visibility by logging what authenticated users did and when they did it.
Question 7
What are the four primary factor categories used in authentication?
• A. Something you know, something you have, something you are,
and somewhere you are (or something you do).
• B. Username, password, email, and phone number.
• C. Hardware token, software token, SMS code, and push
notification.