Certified Identity and Access Professional (CIAP) Practice Exam |
Complete Questions, Answers & Detailed Explanations and
solutions
Question 1
What is the fundamental objective of an Enterprise Identity and Access
Management (IAM) program?
• A. To ensure the right individual accesses the right resources at
the right times for the right reasons.
• B. To eliminate the need for firewalls and network segmentation.
• C. To automate enterprise accounting and tax filing workflows.
• D. To replace physical building security guards with software
tokens.
Correct Answer: A. To ensure the right individual accesses the right
resources at the right times for the right reasons.
Detailed Rationale: The core tenet of IAM is managing digital identities
and controlling access permissions securely and efficiently, ensuring
authorized users gain appropriate access while protecting
organizational assets from unauthorized exposure.
Question 2
What is the primary security goal of the Principle of Least Privilege
(PoLP)?
, • A. Granting users and systems the minimum levels of access
necessary to perform their required job functions and nothing
more.
• B. Providing all employees with administrative privileges to
maximize operational agility.
• C. Ensuring every user shares a single master credential across all
enterprise applications.
• D. Maximizing network latency to prevent automated cyber
attacks.
Correct Answer: A. Granting users and systems the minimum levels of
access necessary to perform their required job functions and nothing
more.
Detailed Rationale: Least privilege minimizes the blast radius of a
security breach or insider threat by ensuring that if an account is
compromised, the attacker's access is strictly bounded.
Question 3
What is the purpose of Separation of Duties (SoD) in access control
governance?
• A. Dividing critical tasks and sensitive workflows among multiple
individuals so no single person has complete end-to-end control.
• B. Requiring every employee to work in two separate physical
office locations.
• C. Splitting network traffic across redundant fiber-optic cables.
, • D. Maintaining two separate active directory domains for
password storage.
Correct Answer: A. Dividing critical tasks and sensitive workflows
among multiple individuals so no single person has complete end-to-
end control.
Detailed Rationale: Separation of duties prevents fraud, error, and
malicious collusion by ensuring high-risk actions (e.g., creating a
financial vendor and approving payments) require collaboration
between distinct parties.
Question 4
What does the "Need-to-Know" principle dictate in information
security?
• A. Access to specific data or resources should be restricted only to
individuals who require that specific information to perform their
official duties.
• B. All employees must read every internal company memo
published on the intranet.
• C. Users must know their manager's personal mobile phone
number before logging in.
• D. Software developers must know the plaintext passwords of all
production database administrators.
Correct Answer: A. Access to specific data or resources should be
restricted only to individuals who require that specific information to
perform their official duties.
, Detailed Rationale: While least privilege refers to functional
permissions, need-to-know governs data confidentiality, ensuring
sensitive records are only viewed by personnel with a legitimate
operational requirement.
Question 5
What is the core philosophy of "Defense in Depth" in IAM architecture?
• A. Relying on multiple, overlapping security layers (such as MFA,
network segmentation, monitoring, and RBAC) so that if one
control fails, others mitigate the risk.
• B. Deploying all security controls at a single perimeter firewall.
• C. Encrypting every file using the exact same static password.
• D. Storing all backup tapes in a single underground vault.
Correct Answer: A. Relying on multiple, overlapping security layers
(such as MFA, network segmentation, monitoring, and RBAC) so that if
one control fails, others mitigate the risk.
Detailed Rationale: Defense in depth eliminates single points of failure,
recognizing that no single security control is impenetrable.
Question 6
What is "Non-Repudiation" in the context of digital identity and
transactions?
• A. A security service that provides proof of the integrity and origin
of data, ensuring an entity cannot successfully deny having
performed an action or transaction.
Complete Questions, Answers & Detailed Explanations and
solutions
Question 1
What is the fundamental objective of an Enterprise Identity and Access
Management (IAM) program?
• A. To ensure the right individual accesses the right resources at
the right times for the right reasons.
• B. To eliminate the need for firewalls and network segmentation.
• C. To automate enterprise accounting and tax filing workflows.
• D. To replace physical building security guards with software
tokens.
Correct Answer: A. To ensure the right individual accesses the right
resources at the right times for the right reasons.
Detailed Rationale: The core tenet of IAM is managing digital identities
and controlling access permissions securely and efficiently, ensuring
authorized users gain appropriate access while protecting
organizational assets from unauthorized exposure.
Question 2
What is the primary security goal of the Principle of Least Privilege
(PoLP)?
, • A. Granting users and systems the minimum levels of access
necessary to perform their required job functions and nothing
more.
• B. Providing all employees with administrative privileges to
maximize operational agility.
• C. Ensuring every user shares a single master credential across all
enterprise applications.
• D. Maximizing network latency to prevent automated cyber
attacks.
Correct Answer: A. Granting users and systems the minimum levels of
access necessary to perform their required job functions and nothing
more.
Detailed Rationale: Least privilege minimizes the blast radius of a
security breach or insider threat by ensuring that if an account is
compromised, the attacker's access is strictly bounded.
Question 3
What is the purpose of Separation of Duties (SoD) in access control
governance?
• A. Dividing critical tasks and sensitive workflows among multiple
individuals so no single person has complete end-to-end control.
• B. Requiring every employee to work in two separate physical
office locations.
• C. Splitting network traffic across redundant fiber-optic cables.
, • D. Maintaining two separate active directory domains for
password storage.
Correct Answer: A. Dividing critical tasks and sensitive workflows
among multiple individuals so no single person has complete end-to-
end control.
Detailed Rationale: Separation of duties prevents fraud, error, and
malicious collusion by ensuring high-risk actions (e.g., creating a
financial vendor and approving payments) require collaboration
between distinct parties.
Question 4
What does the "Need-to-Know" principle dictate in information
security?
• A. Access to specific data or resources should be restricted only to
individuals who require that specific information to perform their
official duties.
• B. All employees must read every internal company memo
published on the intranet.
• C. Users must know their manager's personal mobile phone
number before logging in.
• D. Software developers must know the plaintext passwords of all
production database administrators.
Correct Answer: A. Access to specific data or resources should be
restricted only to individuals who require that specific information to
perform their official duties.
, Detailed Rationale: While least privilege refers to functional
permissions, need-to-know governs data confidentiality, ensuring
sensitive records are only viewed by personnel with a legitimate
operational requirement.
Question 5
What is the core philosophy of "Defense in Depth" in IAM architecture?
• A. Relying on multiple, overlapping security layers (such as MFA,
network segmentation, monitoring, and RBAC) so that if one
control fails, others mitigate the risk.
• B. Deploying all security controls at a single perimeter firewall.
• C. Encrypting every file using the exact same static password.
• D. Storing all backup tapes in a single underground vault.
Correct Answer: A. Relying on multiple, overlapping security layers
(such as MFA, network segmentation, monitoring, and RBAC) so that if
one control fails, others mitigate the risk.
Detailed Rationale: Defense in depth eliminates single points of failure,
recognizing that no single security control is impenetrable.
Question 6
What is "Non-Repudiation" in the context of digital identity and
transactions?
• A. A security service that provides proof of the integrity and origin
of data, ensuring an entity cannot successfully deny having
performed an action or transaction.