• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 94 pages
Exam (elaborations)

WG IDENTITY SECURITY ESSENTIALS PRACTICE EXAM PLUS RATIONALES| INSTANT DOWNLOAD

Document preview thumbnail
Preview 4 out of 94 pages

This practice exam covers key identity security topics including zero trust architecture, RBAC and ABAC, Kerberos delegation, PSD2 SCA, FIDO2/WebAuthn, OAuth 2.1, PAM, SAML, access certification, and credential stuffing detection. Each question includes the correct answer and a rationale to help you understand the reasoning and prepare for the WG Identity Security Essentials exam.

Content preview

, Question 1
A security architect is designing a zero trust architecture for a hybrid cloud
environment. The requirement is to enforce least privilege for
machine-to-machine API calls without relying on static secrets. Which of the
following mechanisms best satisfies this requirement?
A. OAuth 2.0 client credentials flow with long-lived client secrets stored
in a hardware security module (HSM).
B. Mutual TLS (mTLS) with short-lived X.509 certificates issued by an
internal certificate authority and automatically rotated via SPIFFE/SPIRE.
C. SAML 2.0 assertions signed by an identity provider, with session
cookies valid for 8 hours.
D. API keys stored in a secrets manager and injected as environment
variables at runtime.
Correct Answer: B - Mutual TLS (mTLS) with short-lived X.509
certificates issued by an internal certificate authority and
automatically rotated via SPIFFE/SPIRE.


RATIONALE
mTLS with SPIFFE/SPIRE provides cryptographic identity with
automatic rotation, eliminating static secrets and supporting zero trust.
OAuth client secrets, even in HSMs, are still static and long-lived.
SAML is for user authentication, not machine-to-machine. API keys
are static and vulnerable to leakage.

Question 2
An identity governance team is implementing role-based access control
(RBAC) but faces frequent role explosion and entitlement creep. Which
approach best addresses these issues while maintaining least privilege?
A. Adopting attribute-based access control (ABAC) with dynamic
policies evaluated at runtime.
B. Increasing the number of roles to cover every possible job function.


Page 2

, C. Implementing static separation of duties (SoD) with annual manual

reviews.

D. Using discretionary access control (DAC) where resource owners
assign permissions.
Correct Answer: A - Adopting attribute-based access control
(ABAC) with dynamic policies evaluated at runtime.


RATIONALE
ABAC uses attributes and policies to grant fine-grained access
dynamically, reducing role explosion and entitlement creep. More
roles exacerbate the problem. Static SoD and annual reviews are
insufficient for dynamic environments. DAC lacks centralized control
and least privilege enforcement.

Question 3
During a red team exercise, an attacker with valid low-privilege credentials
moved laterally to a domain controller by exploiting a Kerberos delegation
misconfiguration. Which mitigation most effectively prevents this attack?
A. Enforcing unconstrained Kerberos delegation for all service accounts.
B. Implementing resource-based constrained delegation (RBCD) with
strict access controls.
C. Disabling Kerberos armoring (FAST) to improve performance.
D. Using NTLM instead of Kerberos for authentication.
Correct Answer: B - Implementing resource-based constrained
delegation (RBCD) with strict access controls.


RATIONALE
RBCD restricts delegation to specific resources and requires explicit
permissions, mitigating lateral movement via delegation abuse.
Unconstrained delegation is highly vulnerable. Disabling FAST
weakens security. NTLM is less secure and not a mitigation.




Page 3

, Question 4
A financial institution must comply with PSD2's Strong Customer
Authentication (SCA) for online payments. Which combination of factors
satisfies SCA requirements?
A. Password and security question.
B. Fingerprint and one-time password (OTP) sent via SMS.
C. Knowledge-based authentication (KBA) and email link.
D. PIN and a static code printed on the card.
Correct Answer: B - Fingerprint and one-time password (OTP)
sent via SMS.


RATIONALE
SCA requires two independent factors from different categories:
inherence (fingerprint) and possession (OTP via SMS). Password and
security question are both knowledge factors. KBA and email link are
both knowledge/possession but email is not considered strong
possession. PIN and static code are both knowledge/possession but
static code is not dynamic.

Question 5
An organization is adopting FIDO2/WebAuthn for passwordless
authentication. Which statement about the role of the relying party (RP) is
correct?
A. The RP generates and stores the private key on behalf of the user.
B. The RP validates the signature using the public key associated with the
user's authenticator.
C. The RP must store biometric data to verify the user's identity.
D. The RP relies on a shared secret between the authenticator and the
server.
Correct Answer: B - The RP validates the signature using the
public key associated with the user's authenticator.


Page 4

Document information

Uploaded on
September 24, 2026
Number of pages
94
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$28.00

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CaseStudyPro
3.9
(12)
Sold
43
Followers
0
Items
1216
Last sold
4 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions