• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 94 páginas
Examen

WG IDENTITY SECURITY ESSENTIALS PRACTICE EXAM PLUS RATIONALES| INSTANT DOWNLOAD

Document preview thumbnail
Vista previa 4 fuera de 94 páginas

This practice exam covers key identity security topics including zero trust architecture, RBAC and ABAC, Kerberos delegation, PSD2 SCA, FIDO2/WebAuthn, OAuth 2.1, PAM, SAML, access certification, and credential stuffing detection. Each question includes the correct answer and a rationale to help you understand the reasoning and prepare for the WG Identity Security Essentials exam.

Vista previa del contenido

, Question 1
A security architect is designing a zero trust architecture for a hybrid cloud
environment. The requirement is to enforce least privilege for
machine-to-machine API calls without relying on static secrets. Which of the
following mechanisms best satisfies this requirement?
A. OAuth 2.0 client credentials flow with long-lived client secrets stored
in a hardware security module (HSM).
B. Mutual TLS (mTLS) with short-lived X.509 certificates issued by an
internal certificate authority and automatically rotated via SPIFFE/SPIRE.
C. SAML 2.0 assertions signed by an identity provider, with session
cookies valid for 8 hours.
D. API keys stored in a secrets manager and injected as environment
variables at runtime.
Correct Answer: B - Mutual TLS (mTLS) with short-lived X.509
certificates issued by an internal certificate authority and
automatically rotated via SPIFFE/SPIRE.


RATIONALE
mTLS with SPIFFE/SPIRE provides cryptographic identity with
automatic rotation, eliminating static secrets and supporting zero trust.
OAuth client secrets, even in HSMs, are still static and long-lived.
SAML is for user authentication, not machine-to-machine. API keys
are static and vulnerable to leakage.

Question 2
An identity governance team is implementing role-based access control
(RBAC) but faces frequent role explosion and entitlement creep. Which
approach best addresses these issues while maintaining least privilege?
A. Adopting attribute-based access control (ABAC) with dynamic
policies evaluated at runtime.
B. Increasing the number of roles to cover every possible job function.


Page 2

, C. Implementing static separation of duties (SoD) with annual manual

reviews.

D. Using discretionary access control (DAC) where resource owners
assign permissions.
Correct Answer: A - Adopting attribute-based access control
(ABAC) with dynamic policies evaluated at runtime.


RATIONALE
ABAC uses attributes and policies to grant fine-grained access
dynamically, reducing role explosion and entitlement creep. More
roles exacerbate the problem. Static SoD and annual reviews are
insufficient for dynamic environments. DAC lacks centralized control
and least privilege enforcement.

Question 3
During a red team exercise, an attacker with valid low-privilege credentials
moved laterally to a domain controller by exploiting a Kerberos delegation
misconfiguration. Which mitigation most effectively prevents this attack?
A. Enforcing unconstrained Kerberos delegation for all service accounts.
B. Implementing resource-based constrained delegation (RBCD) with
strict access controls.
C. Disabling Kerberos armoring (FAST) to improve performance.
D. Using NTLM instead of Kerberos for authentication.
Correct Answer: B - Implementing resource-based constrained
delegation (RBCD) with strict access controls.


RATIONALE
RBCD restricts delegation to specific resources and requires explicit
permissions, mitigating lateral movement via delegation abuse.
Unconstrained delegation is highly vulnerable. Disabling FAST
weakens security. NTLM is less secure and not a mitigation.




Page 3

, Question 4
A financial institution must comply with PSD2's Strong Customer
Authentication (SCA) for online payments. Which combination of factors
satisfies SCA requirements?
A. Password and security question.
B. Fingerprint and one-time password (OTP) sent via SMS.
C. Knowledge-based authentication (KBA) and email link.
D. PIN and a static code printed on the card.
Correct Answer: B - Fingerprint and one-time password (OTP)
sent via SMS.


RATIONALE
SCA requires two independent factors from different categories:
inherence (fingerprint) and possession (OTP via SMS). Password and
security question are both knowledge factors. KBA and email link are
both knowledge/possession but email is not considered strong
possession. PIN and static code are both knowledge/possession but
static code is not dynamic.

Question 5
An organization is adopting FIDO2/WebAuthn for passwordless
authentication. Which statement about the role of the relying party (RP) is
correct?
A. The RP generates and stores the private key on behalf of the user.
B. The RP validates the signature using the public key associated with the
user's authenticator.
C. The RP must store biometric data to verify the user's identity.
D. The RP relies on a shared secret between the authenticator and the
server.
Correct Answer: B - The RP validates the signature using the
public key associated with the user's authenticator.


Page 4

Información del documento

Subido en
24 de septiembre de 2026
Número de páginas
94
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$28.00

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
CaseStudyPro
3.9
(12)
Vendido
43
Seguidores
0
Artículos
1216
Última venta
6 horas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes