Browse all practice questions for the CISSP Domain 5 Identity and Access Management Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 5 Identity and Access Management Practice Test 2026 - Free CISSP Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which session management solutions can Ben recommend to prevent unauthorized access during lunch hours?
  • What is Kathleen's best option to ensure the users of the passcards are who they are supposed to be?
  • What does port 636 indicate in Jim's LDAP client configuration?
  • In palm scanning, what features are identified as unique to each individual?
  • What concept involves the systematic assignment of access rights based on roles?
  • What do we refer to when describing the biometric identification characteristic of "What you are"?
  • What does the 'lattice-based' model in access controls primarily compartmentalize?
  • Which of the following describes a virtual table created from specific columns of one or more database tables?
  • During the Kerberos logon process, how is the user's username and password protected when sent to the KDC?
  • What is the primary goal of registration in identity management?
  • Which of the following describes a logical access control system?
  • What technique allows users to be created and managed through an on-premises identity provider?
  • What does XACML specifically describe?
  • What does the principle of least privilege entail?
  • If an attacker specifically wants to target a web server, which port is typically scanned?
  • Which access control concept best describes the ability to access information based on a user's specific needs?
  • What does the Nmap tool primarily identify when it scans a system?
  • In which scenario would vulnerability scanning be considered essential?
  • What is the primary goal of access control techniques?
  • In a MAC model, which objects and subjects have a label?
  • The US government CAC is an example of which type of authentication factor?
  • What major issue often results from decentralized access control?
  • When an application allows a logged-in user to perform specific actions, it is an example of what?
  • What is a characteristic of content-dependent access control?
  • What type of password remains the same for each logon?
  • Which principle guarantees that a user will not gain unauthorized access to resources?
  • How much additional complexity does adding a single character to the minimum length of passwords for an organization create?
  • What is the first step in the Kerberos logon process?
  • What do iris scans analyze?
  • Which Type 3 authenticator can be used on its own rather than in combination with other biometric factors?
  • Why is HAVAL not classified as an encryption algorithm?
  • What does 'hybrid' administration signify in access management?
  • Which of the following is a central task of account management systems?
  • When Cris adds a user ID to an identity system, what process has he completed?
  • What is a significant drawback of commonly used password generators?
  • In an access control system, what must be done each time a subject attempts to access an object?
  • In the context of network security, what is a significant advantage of Multi-factor Authentication?
  • Which of the following is a benefit of using Kerberos?
  • During an account review, which aspect is crucial for user access management?
  • Voice pattern recognition is categorized under which type of authentication factor?
  • What is the primary function of Kerberos in network security?
  • What type of attack focuses on exploiting weaknesses in the implementation of a cryptography system?
  • In the context of Identity Governance, what does SSO stand for?
  • What does Lattice-Based Access Control rely on for authorization?
  • What type of process should a company perform to ensure that an employee has appropriate rights?
  • What is an important aspect of accountability in access management?
  • A key feature of role-based access control (RBAC) is:
  • What type of access control model is being leveraged when Alex sets permissions on a Linux server?
  • What authentication protocol does Windows use by default for Active Directory systems?
  • Which of the following is NOT considered an access control layer?
  • Which entity typically manages password recovery processes for social identity applications?
  • Why are salts used with hashes in password storage?
  • Vulnerability scanning tools like Qualys are primarily used for what purpose?
  • Which elements does a thin client approach encompass to guard a network?
  • Which method is often the first type of network reconnaissance performed against a targeted network?
  • What tool can Jim use to allow cloud-based applications to access data on his behalf?
  • What is a significant disadvantage of SSO?
  • What are the four key principles of access control referred to as?
  • What distinguishes a physical access control system from logical access control systems?
  • Which biometric technology would be least favorable for identifying health conditions?
  • What does Discretionary Access Control (DAC) allow concerning the control of access?
  • What is the common target for attackers when they perform port scans?
  • What is a potential outcome of improperly applying separation of duties?
  • What could be a result of decentralized administration in access management?
  • What distinguishes an Access Control List (ACL) from a capability table?
  • Which access control model allows users to have more granular permissions based on system resources?
  • What is a common use for TACACS+ in identity management?
  • Which access control model is typically non-discretionary in nature?
  • What does "constrained interface" mean in the context of security applications?
  • Which of the following is not a type of attack used against access controls?
  • What does separation of duties and responsibilities aim to achieve?
  • What is the main purpose of an Access Control System?
  • What type of access control system is used when a table includes assigned privileges, objects, and subjects to manage access?
  • Which of the following best defines the principle of least privilege?
  • How does the SESAME process handle access privileges?
  • Which of the following is an example of a dynamic token?
  • What is a thin client in the context of identity management?
  • Which component of the KDC generates the encrypted time-stamped Ticket Granting Ticket (TGT)?
  • What is the primary function of access badges in a secured facility?
  • Dog, guards, and fences are examples of what type of control?
  • What type of information does a vulnerability scan typically produce?
  • In an LDAP distinguished name, which component becomes less specific as it progresses from left to right?
  • What defines a one-time password?
  • To enhance security for RADIUS, how should Brian implement encryption?
  • Which of the following AAA protocols is most commonly used in networking environments?
  • What is a passphrase most commonly used for?
  • What is an Access Control Matrix used for?
  • Which control model uses policies to determine access rights but does not allow discretion by the user?
  • How is a unique identifier added to an identity system?
  • What type of access control limits login capabilities to work hours only, as configured in Susan's workstation?
  • What authentication factor would be classified as "something you have"?
  • What is a primary benefit of using electronic authentication?
  • How does the Kerberos client authenticate the server after receiving the TGT?
  • Radio Frequency Identification (RFID) technology is primarily used for what purpose?
  • What do file directories and devices represent in access control models?
  • Which of the following best defines authorization?
  • How prevalent are IP probes on the Internet today?
  • What is primarily needed for establishing trust between a user and a system?
  • When using SYSKEY on Windows systems, what is encrypted in the password store?
  • Which term refers to the access granted for an object that determines what actions can be performed on it?
  • What type of access control is illustrated by a permission listing for different users on a storage device?
  • What is one key benefit of using IDaaS?
  • Which error type in biometric systems is represented by the movement from legitimate access to unauthorized access?
  • What is the primary function of KRYPTOKNIGHT?
  • Which of the following contributes to the administrative overhead of using Kerberos?
  • Mandatory Access Controls (MACs) require what for managing access?
  • Which administration method may lack consistency in procedures?
  • In a lattice-based access control model, what do all objects and subjects have?
  • What action should network administrators take concerning ping functionality?
  • Which of the following is a primary function of logging in accountability?
  • Which of the following is not a valid LDAP distinguished name (DN)?
  • What type of access control is composed of policies and procedures that support regulations and organizational requirements?
  • What should Alex implement to prevent eavesdropping on SAML traffic and ensure authenticity?
  • In Non-Discretionary Access Control, who determines access rights?
  • What does Service Provisioning Markup Language (SPML) specifically relate to?
  • Which of the following is a ticket-based authentication protocol designed to provide secure communication?
  • What process is utilized by Susan's financial services company to verify user identity through past data?
  • Which type of attack targets statistical weaknesses in a cryptosystem?
  • What defines Rule-Based Access Control?
  • Which of the following items is not commonly associated with restricted interfaces?
  • What is the main function of a physical access control system?
  • What does binding a user to appropriate controls involve?
  • What solution is most likely to reduce help desk cases related to password changes?
  • What availability risk does onsite authentication create for traveling users accessing 3rd party applications?
  • What is the primary goal of hacking?
  • What defines a cryptographic device?
  • Which of the following describes a behavioral biometric characteristic?
  • Which model includes global rules that apply to all subjects?
  • What aspect of Active Directory is emphasized for security?
  • Which of the following types of access controls does NOT describe a lock?
  • What is one key advantage of implementing SSO?
  • What is the most likely issue Susan faces if her Kerberos tickets are not accepted, given her setup is properly configured?
  • In an identity-based access control system, who ultimately decides access rights?
  • What does the term 'triviality' refer to in password policies?
  • What is the Crossover Error Rate (CER)?
  • What does the Crossover Error Rate (CER) indicate in a biometric system?
  • What is an essential feature of access control systems?
  • Which aspect is critical when selecting vulnerability scanning tools?
  • In multi-factor authentication, what is the benefit of using multiple factors?
  • What does accountability in a system ensure?
  • What does Identity as a Service (IDaaS) provide?
  • Which access control model restricts access based on user roles?
  • What does a MAC address signify in networking?
  • Role-Based Access Control (RBAC) is based on what principle?
  • Which access control scheme should Susan recommend for flexibility and scalability?
  • What does it mean if the Crossover Error Rate is achieved?
  • Which term best describes a rigid control over access adjustments?
  • Who ultimately decides access permissions in a Discretionary Access Control (DAC) system?
  • What is the primary feature of Single Sign-On (SSO) technology?
  • What is the main purpose of Multi-factor Authentication?
  • Which protocol is primarily used for handling XML-based messaging?
  • What does an increase in the Crossover Error Rate (CER) signify for a biometric authentication system?
  • What is an example of a context-dependent control?
  • What is the purpose of a password checker program?
  • What solution can help address concerns about third parties controlling single sign-on (SSO) directions?
  • What type of access control scheme limits access based on security labels assigned to resources?
  • What role do automated tools play in network reconnaissance?
  • What is the primary advantage of using federated identity?
  • What psychological aspect represents a concern when applying biometric identification?
  • What protocol should Angela monitor to read traffic from a RADIUS server configured with default settings?
  • Which biometric method scans the blood-vessel pattern of the retina?
  • What is the key function of a Password Management System in an enterprise environment?
  • What standards-based markup language should Lauren choose to build her interface for provisioning services?
  • What does a 'closed' port status mean in the context of a network scan?
  • Which protocol is primarily designed for authorization in web applications?
  • Which of the following is a client/server protocol designed to allow network access servers to authenticate remote users?
  • What two important elements does the KDC send to the client after verifying the user's credentials during the Kerberos logon process?
  • Why is monitoring false acceptance and rejection rates important in identity management?
  • What is the acceptable throughput time for biometric systems according to industry standards?
  • Which biometric identification method is usually the most expensive to implement?
  • What is a common concern regarding the use of retina scans for biometric authentication?
  • Google's identity integration with various organizations and applications across domains is an example of what?
  • How does a static password token function in authentication?
  • What is the term for access control that allows user-defined settings?
  • What is a key advantage of using Nmap for scanning systems?
  • RAID-5 is an example of which type of control?
  • Why is it critical to monitor the resources a user is authorized to access?
  • What is SAML primarily used for?
  • Which biometric technology is considered most accurate?
  • What does validity of access control tokens depend on?
  • What is the main characteristic of single factor authentication?
  • What type of technology is Jim implementing for his organization in a cloud identity solution?
  • Which of the following is not considered a weakness in Kerberos?
  • What is the role of facility access control?
  • What method should Lauren use to validate user identities for a banking website?
  • What principle ensures that access to an object is denied unless it has been explicitly granted?
  • What is the recommended option for handling on-site identity needs in an organization using Active Directory for AAA services?
  • What does electronic authentication (e-authentication) establish?
  • What does it signify when Nmap encounters a 'filtered' port during a scan?
  • What type of control involves restricting access based on the internal data of each field?
  • Which pair of factors are key for user acceptance of biometric identification systems?
  • What does a Password Management System accomplish?
  • What can be an outcome of failing to remediate vulnerabilities identified in a scan?
  • What is an example of a Type 1 authentication factor?
  • What does a meta directory do?
  • What is the main focus of an implementation attack?
  • What is the characteristic of a MAC address?
  • Which open protocol was designed to replace RADIUS, providing extensible commands but lacking backward compatibility?
  • What type of attack is most likely to succeed against hashed passwords recovered during a penetration test?
  • Which of the following access control methods allows task-based controls to determine access?
  • In a discretionary access control model, what does the owner of an object do?
  • Which tool is not typically used to verify adherence to a provisioning process that complies with security policy?
  • When a subject claims an identity, what process is being performed?
  • Which factor is NOT considered an advantage of biometric authentication?
  • What replaces NTLM in Windows environments?
  • What must a client do before using the Ticket Granting Ticket (TGT) in the Kerberos authentication process?
  • What type of biometric error occurred when a legitimate user is mistakenly rejected?
  • What is the function of HAVAL in the context of hashing?
  • Which cryptographic method does Kerberos utilize?
  • Which biometric method provides a one-to-many identification by storing full fingerprints?
  • What does the False Acceptance Rate (Type II) represent in identity management?
  • Which identity management method allows for single sign-on (SSO) through the handling of login requests by an on-premises identity provider?
  • What risk is associated with allowing the OpenID relying party to control the connection to the OpenID provider?
  • Callback to a home phone number is an example of what type of authentication factor?
  • Which of the following is not considered a single sign-on (SSO) implementation?
  • In a biometric system, what is the result when the False Acceptance Rate (FAR) is lower?
  • What action are you performing when you input a user ID and password?
  • What differentiates voice prints from other biometric devices?
  • What is the term for the unauthorized interception and use of passwords?
  • Which option best describes the purpose of salting a password hash?
  • Which term describes an attack that uses a predefined list of words to guess passwords?
  • Which scanning tool is known for its ability to automate network vulnerability assessments?
  • What is the key measurement in hand geometry biometrics?
  • Which technique involves probing all active systems on a network for running services?
  • What type of trust must be established to connect an Active Directory environment with an existing Kerberos K5 domain?
  • What type of attack is intended to be prevented by the creation and exchange of state tokens?
  • Which of the following best describes the term "authorization"?
  • What type of authentication factor is represented when using a fingerprint scanner?
  • In the relationship between identity, authentication, and authorization, what does identification provide?
  • What term describes the situation where multiple processes require access to the same resource?
  • What does SSO stand for in the context of identity access management?
  • Which of the following is not part of a Kerberos authentication system?
  • What is an example of a consequence of not conducting regular vulnerability scans?
  • Which of the following controls can be considered a preventive measure against unauthorized access?
  • What role does OAuth 2.0 play in tech systems?
  • What does accountability refer to in the context of identity management?
  • What do account management systems aim to streamline?
  • What authentication technology complements OAuth for identity verification using a RESTful API?
  • In which type of role-based access control is the role applied to multiple applications based on the user's position in the organization?
  • What does a Trusted Platform Module (TPM) primarily provide?
  • Which access control method grants permissions based on the identity of the user?
  • How does the system use access control tokens?
  • Which access control type would incorporate mandatory restrictions based on clearance levels?
  • In an access control model, what does 'RBAC' stand for?
  • What principle ensures that users are only granted access to information necessary for their tasks?
  • When configuring biometric systems, what does the CER (cross-over error rate) represent?
  • How does implicit deny enhance system security?
  • Which scenario best describes Federation?
  • Which encryption methods does SESAME utilize?
  • What type of token-based authentication system uses a challenge/response process?
  • What is the main role of scripting in authentication systems?
  • What type of access control allows a file owner to manage access based on an access control list?
  • Which identity management method involves creating and managing users in a cloud environment?
  • What is the primary function of a virtual directory?
  • Which approach can help in managing user identities across different platforms and services?
  • After performing an IP probe, what is the next step typically taken by an attacker?
  • Which of the following best describes the role of vulnerability scans in cybersecurity?
  • Which framework allows third-party applications limited access to HTTP services?
  • Which access control model is based on the roles assigned to a user in an organization?
  • What type of service does IDaaS represent?
  • What is the primary method of securing passwords in a well-designed web application?
  • Discretionary Access Control (DAC) allows which individual to control access to an object?
  • Which aspect of Kerberos makes it a mature protocol?
  • What is the function of Physical Access Control Systems (PACS)?
  • What authentication factor does biometric authentication primarily rely on?
  • How are permissions related to actions on files?
  • In a scenario where an organization requires multiple forms of login (username, PIN, password, and retina scan), how many distinct types of factors are being used?
  • Which of the following is NOT an example of a vulnerability scanning tool?
  • What does Kerberos primarily address in its security framework?
  • What is the primary purpose of logging in identity management?
  • What is a defining characteristic of Logical Access Controls?
  • What is a brute force attack?
  • What does federated ID management relate to in an SSO context?
  • What is the best way to provide accountability for the use of identities?
  • What is a distinctive characteristic of Rule-BAC models?
  • Which biometric system analyzes the unique characteristics of one's voice?
  • Which of the following best describes a Type 3 authentication factor?
  • What are access control systems designed to do?
  • What type of vulnerabilities do statistical attacks often exploit?
  • What defines the "exploit" in the context of vulnerability scanning?
  • What is the main purpose of the Time-to-Live (TTL) setting in networking configurations?
  • Which service component does Identity as a Service typically provide?
  • What strategy is commonly used in social engineering attacks?
  • What do Keyboard Dynamics primarily focus on capturing?
  • Which characteristic is NOT a component of biometric authentication?
  • Which of the following is a function of a Trusted Platform Module (TPM)?
  • What type of administration allows only one element to configure access controls centrally?
  • Which of the following is not considered a logical or technical access control?
  • In a biometric access control system, what problem may occur if the system is set too high, like at point B?
  • What is the goal of the Needham-Schroeder protocol used in SESAME?
  • In what format does OpenLDAP store the userPassword attribute by default?
  • In biometrics, what is the term used for the rate at which legitimate users are incorrectly rejected?
  • Which of the following verifies identity based on possession?
  • Which term describes controls that establish or enforce a specific action or behavior?
  • Which type of applications restrict what users can do based on their privileges?
  • What type of biometric error occurs if a user logs into another customer's account after scanning their fingerprint?
  • What is a disadvantage of the Kerberos system?
  • Which standard is associated with directory services important for identity systems?
  • Which LDAP authentication mode can provide secure authentication?
  • In password security, what does the term "exhaustive" often refer to?
  • What makes longer passwords more effective?
  • Which classification levels of data can Jim access with his Secret clearance under mandatory access control?
  • What is indicated when a port is labeled 'open' during a port scan?
  • What is a consequence of having a very high false acceptance rate in a biometric system?
  • What does Security Assertion Markup Language 2.0 (SAML 2.0) facilitate?
  • What is the main characteristic of Limited RBAC?
  • What is the main function of XML Signature?
  • Which identity management system method is primarily focused on web applications rather than traditional networks?
  • What does Hybrid RBAC facilitate within an organization?
  • What does a directory service typically provide?
  • When conducting a vulnerability scan, what is the first step an attacker typically performs?
  • What is the main purpose of authentication in identity management?
  • Facial scans evaluate which of the following characteristics?
  • What issue does Lauren encounter when she has access to various systems that are unnecessary for her job?
  • Which of the following is NOT a benefit of using Kerberos?
  • What is the purpose of authorization in access management?
  • Which of the following is not a common threat to access control mechanisms?
  • In which situation might an organization prefer a higher false rejection rate (FRR) over a higher false acceptance rate (FAR) in biometric systems?
  • What process involves verifying an individual’s identity in access management?
  • What is a typical use case for Rule-Based Access Control?
  • Rule-based access control (RBAC) is characterized by:
  • What type of systems do Kerberos, KryptoKnight, and SESAME represent?
  • What term describes the administrative domain for authentication in Kerberos?
  • What does multi-factor authentication aim to achieve?
  • What is a potential risk when using social login for an e-commerce application?
  • Which concept refers to the ability to modify system parameters like the system time?
  • Which access control principle focuses on granting users minimal levels of access?
  • Which of the following best describes the function of an Identity Provider (IdP)?
  • What happens to addresses that do not respond to an IP probe?
  • Which operation involves the allocation of access permissions to users?
  • What should Ben do if the FAR and FRR in his biometric system do not meet acceptable performance levels?
  • What is the main disadvantage of biometric systems regarding enrollment time?
  • What is the role of a User ID in a system?
  • How can policy checking improve password effectiveness?
  • What is the result of implementing Single Sign-On (SSO) for users?
  • What is the primary purpose of performing reconnaissance in a network attack?
  • In terms of authentication factors, what does "something you are" refer to?
  • A sequence of login failures in logs indicates what type of attack?
  • Which system is responsible for user authentication for Google+ users?
  • Which type of authentication method involves a time-based component between a token and an authentication server?
  • What is the main purpose of identity proofing?
  • What is one primary characteristic of a static password?
  • What is one benefit of using multiple vulnerability scanning tools?
  • What type of biometric authenticator is palm scanning classified as?
  • Which access control mechanism identifies users based on their identity and assigns resource ownership accordingly?
  • Which biometric characteristic is known for remaining the same throughout a person's life?
  • What does Rule-Based Access Control (Rule-BAC) use to determine access on a system?
  • If an organization uses a combination of passwords and biometric data to control access, which type of authentication factors are being utilized?
  • In access management, what does 'object' refer to?
  • When the e-commerce application creates an account for a Google+ user, where should that user's passwords be stored?
  • Which system uses pre-determined policies to control logical access?
  • What is a common feature of Access as a Service?
  • In identity management, what is the purpose of Directory Synchronization?
  • What does 'control' imply in access management systems?
  • What best describes "privileges" in the context of access control?
  • What is the most widely used biometric method today?
  • What protocol is commonly employed for authentication in wireless networks, modems, and network devices?
  • Which access control is commonly utilized by firewalls?
  • What service does IDaaS primarily provide for users accessing SaaS applications?
  • What type of LDAP services has Alex configured when using ports 636 and 3269?
  • In a Kerberos environment, what is sent to the Ticket Granting Service (TGS) for resource access?
  • What is a primary weakness of the SESAME authentication process?
  • Ben uses a software-based token that changes its code every minute. What type of token is he using?
  • What is the primary purpose of SAML 2.0?
  • What is a rainbow table used for in cybersecurity?
  • In the context of access management, what does 'access' refer to?
  • How does increasing password complexity impact security?
  • What is an example of a cognitive password?
  • What type of attack can be mitigated by using a trusted path?
  • What characterizes Attribute-based access control (ABAC)?
  • Which of the following is a technique to add complexity to the encryption process?
  • How does authentication contribute to identity management?
  • Which authentication protocol is primarily used by Windows systems?
  • In ABAC, access rights are determined by what?
  • What kind of access control is based on user identity and granted by an administrator?
  • Which roles are defined in the SAML Specification 2.0?
  • In the context of password security, what is the difference between a password checker and a password hacker?
  • What does a dimmed or disabled menu item indicate in a constrained interface?
  • What is a critical requirement for the effective operation of Kerberos?
  • What is an essential feature of password management systems?
  • Which of the following statements about rights is true?
  • Which of the following is best described as an access control model that focuses on subjects and identifies the object that each subject can access?
  • What does the Secure European System for Application in a Multi-Vendor Environment (SESAME) primarily utilize?
  • What aspect does Hand Topology analyze?
  • Which attribute is typically NOT used for user identity management in social identity systems?
  • Microsoft's Active Directory Domain Services is primarily based on which technology?
  • What password requirement will have the highest impact in preventing brute force attacks?
  • Which technology ensures a user can authenticate once and gain access to multiple systems?
  • Mandatory access control is based on what type of model?
  • What is the function of the Key Distribution Center (KDC) in Kerberos?
  • What is a major concern regarding the use of biometrics?
  • Which authentication method uses a nonce sent by the server to generate a one-time password?
  • In biometric systems, what does a higher false rejection rate indicate?
  • What does Signature Dynamics capture when a person writes a signature?
  • What is the name of the stored sample of a biometric characteristic?
  • What does the authentication process involve?
  • What is a Type 2 authentication factor?
  • What type of access control defines a subject's ability to access an object based on their assigned role or tasks?
  • What is a primary purpose of implementing an access control list (ACL)?
  • What is the primary purpose of performing a vulnerability scan?
  • What issue has Alex's company encountered due to his accumulated rights from previous roles?
  • What role does complexity play in password strength?
  • What does the False Rejection Rate (Type I) indicate in authentication systems?
  • Which of the following statements about vulnerability scanning is TRUE?
  • What access control model best describes the limitation of a user not being able to use certain features in a system?
  • Who is considered a 'subject' in access management terms?
  • What type of identity proofing do questions like "What's your pet's name?" represent?
  • What does Access as a Service typically include?
  • Fingerprints consist of which of the following features?
  • Biba is what type of access control model?
  • Which of the following are considered physical devices for Type 2 authentication?
  • What role does SYSKEY play in relation to hashed passwords on Windows?
  • What is the main focus of a capability table?
  • What is a common method for managing Constrained Interface Applications?
  • What does IDaaS stand for?
  • Which of the following types of scans is often performed in conjunction with vulnerability scanning?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy