CIAP-001 Certification Exam actual Prep | Identity & Access
Management Practice Questions & Detailed Rationales
Question 1
What does the AAA framework stand for in information security and
access management?
• A. Authentication, Authorization, and Accounting
• B. Access, Application, and Auditing
• C. Automation, Administration, and Attribution
• D. Assertion, Authority, and Accountability
Correct Answer: A. Authentication, Authorization, and Accounting
Detailed Rationale: The AAA framework is the foundational security
model for controlling access to computer resources, enforcing security
policies, and tracking user activity for auditing and forensics.
Question 2
What is the primary difference between Authentication and
Authorization?
• A. Authentication verifies who you are (identity verification), while
authorization determines what you are allowed to do (permission
granting).
• B. Authentication encrypts data at rest, while authorization
encrypts data in transit.
, • C. Authentication is performed by network routers, while
authorization is performed by web browsers.
• D. Authentication occurs after session termination, while
authorization occurs during login.
Correct Answer: A. Authentication verifies who you are (identity
verification), while authorization determines what you are allowed to
do (permission granting).
Detailed Rationale: Authentication answers "Who are you?" (e.g.,
entering a password and MFA), whereas authorization answers "What
are you permitted to access?" based on your assigned roles or
attributes.
Question 3
What is the Principle of Least Privilege (PoLP)?
• A. Giving users and system processes only the minimum necessary
access privileges required to perform their specific job functions,
and nothing more.
• B. Granting all users full administrative rights to simplify IT help
desk troubleshooting.
• C. Eliminating passwords entirely in favor of biometric scanning.
• D. Restricting network bandwidth to conserve enterprise storage.
Correct Answer: A. Giving users and system processes only the
minimum necessary access privileges required to perform their specific
job functions, and nothing more.
,Detailed Rationale: PoLP minimizes the blast radius of a security breach
or insider threat by ensuring compromised accounts cannot access
sensitive systems outside their operational scope.
Question 4
What is the "Need-to-Know" principle in access control?
• A. Restricting access to specific data or information assets strictly
to individuals who require that precise information to fulfill their
legitimate professional duties.
• B. Requiring employees to memorize all company security policies
before starting work.
• C. Encrypting all emails sent between departmental colleagues.
• D. Publishing corporate financial records on public web portals.
Correct Answer: A. Restricting access to specific data or information
assets strictly to individuals who require that precise information to
fulfill their legitimate professional duties.
Detailed Rationale: Need-to-know extends the principle of least
privilege specifically to data confidentiality, preventing unnecessary
browsing or exposure of sensitive corporate records.
Question 5
What constitutes a "Digital Identity" in enterprise IAM?
• A. A unique set of attributes, credentials, and identifiers
associated with a distinct entity (human, service account, or
device) within a digital system.
• B. A physical plastic ID badge worn around an employee's neck.
, • C. An IP address assigned to a network router interface.
• D. A digital certificate used exclusively for encrypting hard disk
partitions.
Correct Answer: A. A unique set of attributes, credentials, and
identifiers associated with a distinct entity (human, service account, or
device) within a digital system.
Detailed Rationale: A digital identity serves as the proxy for real-world
entities in digital systems, binding authentication credentials and
authorization attributes together.
Question 6
What are the typical phases of the Identity Lifecycle Management
process?
• A. Onboarding (Provisioning), Role Changes
(Maintenance/Modifications), and Offboarding (Deprovisioning).
• B. Password creation, password expiration, and password
deletion.
• C. Network discovery, vulnerability scanning, and patch
management.
• D. Firewall configuration, rule testing, and log archiving.
Correct Answer: A. Onboarding (Provisioning), Role Changes
(Maintenance/Modifications), and Offboarding (Deprovisioning).
Detailed Rationale: Identity lifecycle management governs an account
from the moment an individual joins an organization, through internal
role transfers, until final departure and access revocation.
Management Practice Questions & Detailed Rationales
Question 1
What does the AAA framework stand for in information security and
access management?
• A. Authentication, Authorization, and Accounting
• B. Access, Application, and Auditing
• C. Automation, Administration, and Attribution
• D. Assertion, Authority, and Accountability
Correct Answer: A. Authentication, Authorization, and Accounting
Detailed Rationale: The AAA framework is the foundational security
model for controlling access to computer resources, enforcing security
policies, and tracking user activity for auditing and forensics.
Question 2
What is the primary difference between Authentication and
Authorization?
• A. Authentication verifies who you are (identity verification), while
authorization determines what you are allowed to do (permission
granting).
• B. Authentication encrypts data at rest, while authorization
encrypts data in transit.
, • C. Authentication is performed by network routers, while
authorization is performed by web browsers.
• D. Authentication occurs after session termination, while
authorization occurs during login.
Correct Answer: A. Authentication verifies who you are (identity
verification), while authorization determines what you are allowed to
do (permission granting).
Detailed Rationale: Authentication answers "Who are you?" (e.g.,
entering a password and MFA), whereas authorization answers "What
are you permitted to access?" based on your assigned roles or
attributes.
Question 3
What is the Principle of Least Privilege (PoLP)?
• A. Giving users and system processes only the minimum necessary
access privileges required to perform their specific job functions,
and nothing more.
• B. Granting all users full administrative rights to simplify IT help
desk troubleshooting.
• C. Eliminating passwords entirely in favor of biometric scanning.
• D. Restricting network bandwidth to conserve enterprise storage.
Correct Answer: A. Giving users and system processes only the
minimum necessary access privileges required to perform their specific
job functions, and nothing more.
,Detailed Rationale: PoLP minimizes the blast radius of a security breach
or insider threat by ensuring compromised accounts cannot access
sensitive systems outside their operational scope.
Question 4
What is the "Need-to-Know" principle in access control?
• A. Restricting access to specific data or information assets strictly
to individuals who require that precise information to fulfill their
legitimate professional duties.
• B. Requiring employees to memorize all company security policies
before starting work.
• C. Encrypting all emails sent between departmental colleagues.
• D. Publishing corporate financial records on public web portals.
Correct Answer: A. Restricting access to specific data or information
assets strictly to individuals who require that precise information to
fulfill their legitimate professional duties.
Detailed Rationale: Need-to-know extends the principle of least
privilege specifically to data confidentiality, preventing unnecessary
browsing or exposure of sensitive corporate records.
Question 5
What constitutes a "Digital Identity" in enterprise IAM?
• A. A unique set of attributes, credentials, and identifiers
associated with a distinct entity (human, service account, or
device) within a digital system.
• B. A physical plastic ID badge worn around an employee's neck.
, • C. An IP address assigned to a network router interface.
• D. A digital certificate used exclusively for encrypting hard disk
partitions.
Correct Answer: A. A unique set of attributes, credentials, and
identifiers associated with a distinct entity (human, service account, or
device) within a digital system.
Detailed Rationale: A digital identity serves as the proxy for real-world
entities in digital systems, binding authentication credentials and
authorization attributes together.
Question 6
What are the typical phases of the Identity Lifecycle Management
process?
• A. Onboarding (Provisioning), Role Changes
(Maintenance/Modifications), and Offboarding (Deprovisioning).
• B. Password creation, password expiration, and password
deletion.
• C. Network discovery, vulnerability scanning, and patch
management.
• D. Firewall configuration, rule testing, and log archiving.
Correct Answer: A. Onboarding (Provisioning), Role Changes
(Maintenance/Modifications), and Offboarding (Deprovisioning).
Detailed Rationale: Identity lifecycle management governs an account
from the moment an individual joins an organization, through internal
role transfers, until final departure and access revocation.