Practice Exam 2026 Edition
Q1.
An organization is implementing an enterprise IAM program. Which governance activity should be
performed FIRST to ensure long-term success?
A. Deploy MFA across all systems
B. Define IAM policies aligned with business objectives
C. Purchase an Identity Governance platform
D. Conduct quarterly access reviews
Answer: B
Explanation:
IAM governance begins with establishing policies, standards, and business objectives. Technology
implementation should follow governance definitions rather than drive them.
Q2.
A company wants to ensure that no employee can both create a vendor and approve vendor
payments. Which IAM governance principle addresses this requirement?
A. Federation
B. Role Mining
C. Segregation of Duties (SoD)
D. Adaptive Authentication
Answer: C
Explanation:
Segregation of Duties prevents conflicts of interest and fraud by separating incompatible
responsibilities among different users.
Q3.
Which metric provides the BEST indication of identity lifecycle management effectiveness?
A. Number of MFA tokens issued
B. Percentage of accounts deprovisioned within SLA after termination
C. Number of firewall rules implemented
D. Password complexity score
Answer: B
Explanation:
Prompt deprovisioning reduces insider threats and orphaned accounts, making it a key lifecycle
management KPI.
, Certified Identity and Access Manager CIAM
Practice Exam 2026 Edition
Q4.
An employee transfers from Finance to Human Resources. What lifecycle event has occurred?
A. Joiner Event
B. Mover Event
C. Leaver Event
D. Federation Event
Answer: B
Explanation:
A mover event occurs when an individual's role or department changes, requiring entitlement
adjustments.
Q5.
Which access control model grants permissions based primarily on organizational job functions?
A. DAC
B. MAC
C. RBAC
D. ABAC
Answer: C
Explanation:
Role-Based Access Control associates permissions with business roles, simplifying administration.
Q6.
A security architect wants access decisions to consider department, location, device trust level, and
time of day. Which model is MOST suitable?
A. DAC
B. RBAC
C. MAC
D. ABAC
Answer: D
Explanation:
Attribute-Based Access Control evaluates multiple attributes dynamically for fine-grained
authorization.
Q7.
Which authentication factor category does a fingerprint belong to?
, Certified Identity and Access Manager CIAM
Practice Exam 2026 Edition
A. Knowledge Factor
B. Possession Factor
C. Behavioral Factor
D. Inherence Factor
Answer: D
Explanation:
Biometric identifiers such as fingerprints are inherence factors because they represent physical
characteristics.
Q8.
A user enters a password and approves a mobile push notification. This is an example of:
A. Single-Factor Authentication
B. Multi-Factor Authentication
C. Passwordless Authentication
D. Delegated Authentication
Answer: B
Explanation:
The password is a knowledge factor and the mobile device approval is a possession factor.
Q9.
Which protocol is primarily used to provide federated authentication for modern web applications
using JSON tokens?
A. LDAP
B. Kerberos
C. OpenID Connect
D. RADIUS
Answer: C
Explanation:
OpenID Connect extends OAuth 2.0 and uses JSON Web Tokens for identity assertions.
Q10.
What is the PRIMARY objective of access certification campaigns?
A. Increase login speed
B. Verify access appropriateness and remove excessive privileges
C. Reduce network latency
D. Enable SSO
, Certified Identity and Access Manager CIAM
Practice Exam 2026 Edition
Answer: B
Explanation:
Access reviews validate that users retain only authorized access.
Q11.
An IAM auditor discovers accounts that remain active 90 days after employee termination. What risk
is MOST significant?
A. Weak encryption
B. Credential stuffing
C. Orphaned account exploitation
D. DNS poisoning
Answer: C
Explanation:
Orphaned accounts create opportunities for unauthorized access without accountability.
Q12.
Which IAM principle grants users only the permissions necessary to perform assigned duties?
A. Federation Trust
B. Least Privilege
C. Delegated Administration
D. Password Rotation
Answer: B
Explanation:
Least privilege minimizes attack surface and reduces impact of compromised accounts.
Q13.
A company requires executives to reauthenticate when accessing highly sensitive payroll data despite
already being logged in. This is known as:
A. Identity Proofing
B. Step-Up Authentication
C. Federation Brokering
D. Account Correlation
Answer: B
Explanation:
Step-up authentication requires additional verification when accessing higher-risk resources.