CISSP DOMAIN 5 IDENTITY
AND ACCESS
MANAGEMENT PRACTICE
TEST 100 QUESTIONS
Question 1: A company wants to reduce the chance that a stolen proximity badge
alone can be used to enter its data center after business hours. Which control BEST addresses this risk?
Choices:
1) Require a badge plus a PIN at the data center entrance 2) Increase the badge read range 3) Allow guards to visually recognize frequent visitors 4) Issue identical spare badges to each team
Correct Answer: Require a badge plus a PIN at the data center entrance
Explanation: Requiring both a badge and a PIN combines a possession factor with a knowledge factor. A stolen badge alone would therefore be insucient for entry.Page 1
Question 2: A research repository contains projects that are all classied at the same sensitivity level, but users should see only projects they are assigned to.Which principle is MOST important in deciding access?
Choices:
1) Availability 2) Nonrepudiation 3) Data remanence 4) Need to know
Correct Answer: Need to know
Explanation: Need to know limits access to information to users whose job responsibilities require that specic information, even when they otherwise hold an appropriate clearance or role.
Question 3: An API gateway must authenticate an automated billing process that
runs without a human user. What type of identity should be used?
Choices:
1) An anonymous guest identity 2) The personal account of the application developer 3) A named service identity dedicated to the billing process 4) A shared employee account
Correct Answer: A named service identity dedicated to the billing process
Explanation: A dedicated service identity provides a distinct nonhuman identity that can be granted only the permissions required by the process and can be audited independently.Page 2
Question 4: Security discovers that employees regularly hold a secure door open for coworkers who have not presented credentials. Which control would BEST reduce this exposure?
Choices:
1) More complex workstation passwords 2) An anti-passback or mantrap design that requires each person to authenticate 3) Longer badge expiration periods 4) A larger visitor lobby
Correct Answer: An anti-passback or mantrap design that requires each person to
authenticate Explanation: Controls that force each individual to authenticate at the physical boundary directly address tailgating and piggybacking. Workstation password settings do not correct the physical access weakness.
Question 5: A company allows only managed laptops with current endpoint
protection to connect to an internal administrative network. Which access decision input is being emphasized?
Choices:
1) Data ownership 2) Password history 3) User job title only 4) Device security posture
Correct Answer: Device security posture
Explanation: Device security posture evaluates the condition and trustworthiness of the endpoint, such as management state and security controls, before granting network access.Page 3