CompTIA Security+ SY0-701 Identity and Access Management Practice Test 4

 

Topic 19 Practice Test 4 covers Identity and Access Management for CompTIA Security+ SY0-701 and maps to objective 4.6: Given a scenario, implement and maintain identity and access management. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

The team is resolving a gap found during an identity and privileged-access design review: it needs trust arrangement that lets identities from one security domain access resources in another without separate local credentials. Which option is most appropriate?

  1. An answer to a personal knowledge question
  2. Least privilege
  3. User provisioning
  4. Federation

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. The requirement maps directly to this function, whereas User provisioning is aimed at creation and assignment of accounts, attributes, groups, and access for an identity.

Incorrect Answers

 

Answer A is incorrect because A personal knowledge answer does not authenticate a physical authenticator or establish possession. This could be appropriate elsewhere, but the required function is trust arrangement that lets identities from one security domain access resources in another without separate local credentials; that makes Federation the precise choice.

Answer B is incorrect because Least privilege means the principle of granting only the access required to perform assigned duties. That concept can be valid in another scenario, but this question is testing trust arrangement that lets identities from one security domain access resources in another without separate local credentials; Federation therefore fits the requirement more directly.

Answer C is incorrect because User provisioning means creation and assignment of accounts, attributes, groups, and access for an identity. The concept is valid, but it does not match this stem. The required function is trust arrangement that lets identities from one security domain access resources in another without separate local credentials, which maps to Federation.

 

Question 2

Reviewers working through an identity and privileged-access design review identify three separate needs: access model that assigns permissions to job roles and then assigns users to those roles; software that securely stores and often generates unique credentials; processes and tools that tightly control, monitor, and audit administrative or high-impact access. Which THREE choices map to those needs? Choose THREE.

  1. Attestation
  2. Multifactor authentication
  3. Role-based access control (RBAC)
  4. Password manager
  5. A physical authenticator that establishes possession
  6. Privileged access management (PAM)

Correct Answers: C, D, F

Correct Answers

 

 

Answer C is correct because Role-based access control (RBAC) means an access model that assigns permissions to job roles and then assigns users to those roles. The fixed-count item needs this function in the answer set. Multifactor authentication covers authentication using factors from more than one category such as knowledge, possession, or inherence, a different requirement.

Answer D is correct because Password manager means software that securely stores and often generates unique credentials. One required function is exactly what this option provides. Multifactor authentication may be useful elsewhere, but it is used for authentication using factors from more than one category such as knowledge, possession, or inherence.

Answer F is correct because Privileged access management (PAM) means processes and tools that tightly control, monitor, and audit administrative or high-impact access. This option satisfies a specific requirement in the stem; Attestation serves formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Attestation means formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid. The fixed-count answer set is Role-based access control (RBAC), Password manager, Privileged access management (PAM); this option does not fill one of those named functions.

Answer B is incorrect because Multifactor authentication means authentication using factors from more than one category such as knowledge, possession, or inherence. The scenario calls for Role-based access control (RBAC), Password manager, Privileged access management (PAM). Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because A biometric comparison must be combined with authentication of a physical authenticator. The question requires exactly 3 selections: Role-based access control (RBAC), Password manager, Privileged access management (PAM). This option falls outside that required set.

 

Question 3

During an identity and privileged-access design review, the team has two independent requirements: (1) access model that evaluates attributes of users, resources, actions, and environment; and (2) processes and tools that tightly control, monitor, and audit administrative or high-impact access. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Multifactor authentication
  2. Privileged access management (PAM)
  3. Federation
  4. Attribute-based access control (ABAC)
  5. Least privilege

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Privileged access management (PAM) means processes and tools that tightly control, monitor, and audit administrative or high-impact access. The fixed-count item needs this function in the answer set. Multifactor authentication covers authentication using factors from more than one category such as knowledge, possession, or inherence, a different requirement.

Answer D is correct because Attribute-based access control (ABAC) means an access model that evaluates attributes of users, resources, actions, and environment. The fixed-count item needs this function in the answer set. Multifactor authentication covers authentication using factors from more than one category such as knowledge, possession, or inherence, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Multifactor authentication means authentication using factors from more than one category such as knowledge, possession, or inherence. The fixed-count answer set is Attribute-based access control (ABAC), Privileged access management (PAM); this option does not fill one of those named functions.

Answer C is incorrect because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. The question requires exactly 2 selections: Attribute-based access control (ABAC), Privileged access management (PAM). This option falls outside that required set.

Answer E is incorrect because Least privilege means the principle of granting only the access required to perform assigned duties. The question requires exactly 2 selections: Attribute-based access control (ABAC), Privileged access management (PAM). This option falls outside that required set.

 

Question 4

The control set for an identity and privileged-access design review must address both protocol for querying and modifying directory services containing identities and related attributes and principle of granting only the access required to perform assigned duties. Which TWO choices map directly to those needs? Choose TWO.

  1. Least privilege
  2. Discretionary access control (DAC)
  3. LDAP
  4. Federation
  5. User provisioning

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Least privilege means the principle of granting only the access required to perform assigned duties. This option satisfies a specific requirement in the stem; Discretionary access control (DAC) serves an access model in which resource owners can grant or modify access permissions and therefore is not interchangeable with it.

Answer C is correct because LDAP means a protocol for querying and modifying directory services containing identities and related attributes. This option satisfies a specific requirement in the stem; Discretionary access control (DAC) serves an access model in which resource owners can grant or modify access permissions and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Discretionary access control (DAC) means an access model in which resource owners can grant or modify access permissions. The fixed-count answer set is Least privilege, LDAP; this option does not fill one of those named functions.

Answer D is incorrect because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. The scenario calls for Least privilege, LDAP. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because User provisioning means creation and assignment of accounts, attributes, groups, and access for an identity. The scenario calls for Least privilege, LDAP. Selecting this option would leave one of those required functions uncovered. For example, LDAP is required for a protocol for querying and modifying directory services containing identities and related attributes.

 

Question 5

A review during an identity and privileged-access design review identifies two gaps. One requires principle of granting only the access required to perform assigned duties. The other requires controlled storage and checkout or brokering of privileged credentials. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Password vaulting
  2. Least privilege
  3. Role-based access control (RBAC)
  4. Hardware token
  5. Ephemeral credential

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Password vaulting means controlled storage and checkout or brokering of privileged credentials. The fixed-count item needs this function in the answer set. Role-based access control (RBAC) covers an access model that assigns permissions to job roles and then assigns users to those roles, a different requirement.

Answer B is correct because Least privilege means the principle of granting only the access required to perform assigned duties. This selection maps directly to one of the named needs. Role-based access control (RBAC) addresses an access model that assigns permissions to job roles and then assigns users to those roles, so it does not satisfy the same slot.

Incorrect Answers

 

Answer C is incorrect because Role-based access control (RBAC) means an access model that assigns permissions to job roles and then assigns users to those roles. The question requires exactly 2 selections: Password vaulting, Least privilege. This option falls outside that required set.

Answer D is incorrect because Hardware token means a physical device that generates, stores, or proves possession of authentication material. The question requires exactly 2 selections: Password vaulting, Least privilege. This option falls outside that required set. For example, Password vaulting is required for controlled storage and checkout or brokering of privileged credentials.

Answer E is incorrect because Ephemeral credential means a short-lived credential created for a limited session or task. The fixed-count answer set is Password vaulting, Least privilege; this option does not fill one of those named functions. For example, Password vaulting is required for controlled storage and checkout or brokering of privileged credentials.

 

Question 6

The team is resolving a gap found during an identity and privileged-access design review: it needs authorization framework that lets a user grant an application limited access to a resource without sharing the user’s password with that application. Which option is most appropriate?

  1. OAuth
  2. Password vaulting
  3. Hardware token
  4. LDAP

Correct Answer: A

Correct Answer

 

 

Answer A is correct because OAuth means an authorization framework that lets a user grant an application limited access to a resource without sharing the user’s password with that application. That makes it the best answer here; Hardware token addresses a physical device that generates, stores, or proves possession of authentication material, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Password vaulting means controlled storage and checkout or brokering of privileged credentials. The question is not asking for this function. It is testing an authorization framework that lets a user grant an application limited access to a resource without sharing the user’s password with that application, so OAuth is the stronger fit.

Answer C is incorrect because Hardware token means a physical device that generates, stores, or proves possession of authentication material. That concept can be valid in another scenario, but this question is testing an authorization framework that lets a user grant an application limited access to a resource without sharing the user’s password with that application; OAuth therefore fits the requirement more directly.

Answer D is incorrect because LDAP means a protocol for querying and modifying directory services containing identities and related attributes. The concept is valid, but it does not match this stem. The required function is an authorization framework that lets a user grant an application limited access to a resource without sharing the user’s password with that application, which maps to OAuth.

 

Question 7

The team is resolving a gap found during an identity and privileged-access design review: it needs another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator. Which option is most appropriate?

  1. A second biometric characteristic without a physical authenticator
  2. Hardware token
  3. A password as the only additional mechanism
  4. Attestation

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator. This is the precise fit for the scenario. Attestation serves the different purpose of formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid.

Incorrect Answers

 

Answer B is incorrect because Hardware token means a physical device that generates, stores, or proves possession of authentication material. The key mismatch is functional: A second biometric characteristic without a physical authenticator addresses Another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator, the need stated by the question.

Answer C is incorrect because A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance. The scenario instead requires Another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator, which is why A second biometric characteristic without a physical authenticator is the better answer; this option serves the different function defined above.

Answer D is incorrect because Attestation means formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid. The concept is valid, but it does not match this stem. The required function is Another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator, which maps to A second biometric characteristic without a physical authenticator.

 

Question 8

During an identity and privileged-access design review, the team needs access model in which centrally defined labels and policy determine access and users cannot freely change permissions. Which option best meets this requirement?

  1. Multifactor authentication
  2. Mandatory access control (MAC)
  3. Just-in-time permission
  4. Password vaulting

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Mandatory access control (MAC) means an access model in which centrally defined labels and policy determine access and users cannot freely change permissions. That is the function the question is testing. Just-in-time permission would instead be used for temporary elevation granted only when needed and removed automatically after a short period.

Incorrect Answers

 

Answer A is incorrect because Multifactor authentication means authentication using factors from more than one category such as knowledge, possession, or inherence. The key mismatch is functional: Mandatory access control (MAC) addresses an access model in which centrally defined labels and policy determine access and users cannot freely change permissions, the need stated by the question.

Answer C is incorrect because Just-in-time permission means temporary elevation granted only when needed and removed automatically after a short period. The concept is valid, but it does not match this stem. The required function is an access model in which centrally defined labels and policy determine access and users cannot freely change permissions, which maps to Mandatory access control (MAC).

Answer D is incorrect because Password vaulting means controlled storage and checkout or brokering of privileged credentials. The concept is valid, but it does not match this stem. The required function is an access model in which centrally defined labels and policy determine access and users cannot freely change permissions, which maps to Mandatory access control (MAC).

 

Question 9

As part of an identity and privileged-access design review, reviewers identify a need for authentication arrangement that lets a user authenticate once and access multiple integrated services. Which option should they select?

  1. A physical authenticator that establishes possession
  2. SAML
  3. Privileged access management (PAM)
  4. Single sign-on (SSO)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Single sign-on (SSO) means authentication arrangement that lets a user authenticate once and access multiple integrated services. That is the function the question is testing. A physical authenticator that establishes possession would instead be used for A biometric comparison must be combined with authentication of a physical authenticator.

Incorrect Answers

 

Answer A is incorrect because A biometric comparison must be combined with authentication of a physical authenticator. The scenario instead requires authentication arrangement that lets a user authenticate once and access multiple integrated services, which is why Single sign-on (SSO) is the better answer; this option serves the different function defined above.

Answer B is incorrect because SAML means an XML-based standard commonly used to exchange authentication and authorization assertions between identity providers and service providers. The concept is valid, but it does not match this stem. The required function is authentication arrangement that lets a user authenticate once and access multiple integrated services, which maps to Single sign-on (SSO).

Answer C is incorrect because Privileged access management (PAM) means processes and tools that tightly control, monitor, and audit administrative or high-impact access. The concept is valid, but it does not match this stem. The required function is authentication arrangement that lets a user authenticate once and access multiple integrated services, which maps to Single sign-on (SSO).

 

Question 10

A review during an identity and privileged-access design review identifies two gaps. One requires access model in which resource owners can grant or modify access permissions. The other requires biometric comparison must be combined with authentication of a physical authenticator. The physical authenticator establishes possession, while the biometric comparison supplies an inherence factor. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Discretionary access control (DAC)
  2. User deprovisioning
  3. Attestation
  4. Attribute-based access control (ABAC)
  5. A physical authenticator that establishes possession

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Discretionary access control (DAC) means an access model in which resource owners can grant or modify access permissions. This selection maps directly to one of the named needs. Attribute-based access control (ABAC) addresses an access model that evaluates attributes of users, resources, actions, and environment, so it does not satisfy the same slot.

Answer E is correct because A biometric comparison must be combined with authentication of a physical authenticator. The fixed-count item needs this function in the answer set. Attestation covers formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid, a different requirement.

Incorrect Answers

 

Answer B is incorrect because User deprovisioning means removal or disabling of accounts and permissions when access is no longer required. The question requires exactly 2 selections: A physical authenticator that establishes possession, Discretionary access control (DAC). This option falls outside that required set.

Answer C is incorrect because Attestation means formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid. Every answer slot must map to a stated requirement. The correct set is A physical authenticator that establishes possession, Discretionary access control (DAC), so this option cannot replace one of those selections.

Answer D is incorrect because Attribute-based access control (ABAC) means an access model that evaluates attributes of users, resources, actions, and environment. The required choices are A physical authenticator that establishes possession, Discretionary access control (DAC). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 11

A security engineer is working through an identity and privileged-access design review. The immediate requirement is password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance. Which choice is the best fit?

  1. Biometric factor
  2. An answer to a personal knowledge question
  3. A password as the only additional mechanism
  4. User deprovisioning

Correct Answer: C

Correct Answer

 

 

Answer C is correct because A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance. The deciding point is functional fit: this option covers the stated need, while Biometric factor addresses an authentication factor based on a physical or behavioral characteristic of a person.

Incorrect Answers

 

Answer A is incorrect because Biometric factor means an authentication factor based on a physical or behavioral characteristic of a person. The concept is valid, but it does not match this stem. The required function is A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance, which maps to A password as the only additional mechanism.

Answer B is incorrect because A personal knowledge answer does not authenticate a physical authenticator or establish possession. The scenario instead requires A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance, which is why A password as the only additional mechanism is the better answer; this option serves the different function defined above.

Answer D is incorrect because User deprovisioning means removal or disabling of accounts and permissions when access is no longer required. The scenario instead requires A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance, which is why A password as the only additional mechanism is the better answer; this option serves the different function defined above.

 

Question 12

A security engineer is working through an identity and privileged-access design review. The immediate requirement is physical device that generates, stores, or proves possession of authentication material. Which choice is the best fit?

  1. Hardware token
  2. Federation
  3. SAML
  4. User provisioning

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Hardware token means a physical device that generates, stores, or proves possession of authentication material. The requirement maps directly to this function, whereas Federation is aimed at trust arrangement that lets identities from one security domain access resources in another without separate local credentials.

Incorrect Answers

 

Answer B is incorrect because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. The concept is valid, but it does not match this stem. The required function is a physical device that generates, stores, or proves possession of authentication material, which maps to Hardware token.

Answer C is incorrect because SAML means an XML-based standard commonly used to exchange authentication and authorization assertions between identity providers and service providers. This could be appropriate elsewhere, but the required function is a physical device that generates, stores, or proves possession of authentication material; that makes Hardware token the precise choice.

Answer D is incorrect because User provisioning means creation and assignment of accounts, attributes, groups, and access for an identity. The question is not asking for this function. It is testing a physical device that generates, stores, or proves possession of authentication material, so Hardware token is the stronger fit.

 

Question 13

As part of an identity and privileged-access design review, reviewers identify a need for controlled storage and checkout or brokering of privileged credentials. Which option should they select?

  1. Biometric factor
  2. Discretionary access control (DAC)
  3. Password vaulting
  4. User deprovisioning

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Password vaulting means controlled storage and checkout or brokering of privileged credentials. The requirement maps directly to this function, whereas User deprovisioning is aimed at removal or disabling of accounts and permissions when access is no longer required.

Incorrect Answers

 

Answer A is incorrect because Biometric factor means an authentication factor based on a physical or behavioral characteristic of a person. The key mismatch is functional: Password vaulting addresses controlled storage and checkout or brokering of privileged credentials, the need stated by the question.

Answer B is incorrect because Discretionary access control (DAC) means an access model in which resource owners can grant or modify access permissions. The concept is valid, but it does not match this stem. The required function is controlled storage and checkout or brokering of privileged credentials, which maps to Password vaulting.

Answer D is incorrect because User deprovisioning means removal or disabling of accounts and permissions when access is no longer required. That concept can be valid in another scenario, but this question is testing controlled storage and checkout or brokering of privileged credentials; Password vaulting therefore fits the requirement more directly.

 

Question 14

The control set for an identity and privileged-access design review must address both access model in which centrally defined labels and policy determine access and users cannot freely change permissions and short-lived credential created for a limited session or task. Which TWO choices map directly to those needs? Choose TWO.

  1. Ephemeral credential
  2. A physical authenticator that establishes possession
  3. Mandatory access control (MAC)
  4. An answer to a personal knowledge question
  5. A password as the only additional mechanism

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Ephemeral credential means a short-lived credential created for a limited session or task. This option satisfies a specific requirement in the stem; A password as the only additional mechanism serves A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance and therefore is not interchangeable with it.

Answer C is correct because Mandatory access control (MAC) means an access model in which centrally defined labels and policy determine access and users cannot freely change permissions. This selection maps directly to one of the named needs. An answer to a personal knowledge question addresses A personal knowledge answer does not authenticate a physical authenticator or establish possession, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because A biometric comparison must be combined with authentication of a physical authenticator. Every answer slot must map to a stated requirement. The correct set is Mandatory access control (MAC), Ephemeral credential, so this option cannot replace one of those selections.

Answer D is incorrect because A personal knowledge answer does not authenticate a physical authenticator or establish possession. The question requires exactly 2 selections: Mandatory access control (MAC), Ephemeral credential. This option falls outside that required set. For example, Ephemeral credential is required for a short-lived credential created for a limited session or task.

Answer E is incorrect because A password supplies a knowledge factor but does not establish possession of the physical authenticator required by the cited guidance. The required choices are Mandatory access control (MAC), Ephemeral credential. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 15

A security engineer is working through an identity and privileged-access design review. The immediate requirement is temporary elevation granted only when needed and removed automatically after a short period. Which choice is the best fit?

  1. Password manager
  2. Just-in-time permission
  3. Multifactor authentication
  4. Attribute-based access control (ABAC)

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Just-in-time permission means temporary elevation granted only when needed and removed automatically after a short period. That is the function the question is testing. Attribute-based access control (ABAC) would instead be used for an access model that evaluates attributes of users, resources, actions, and environment.

Incorrect Answers

 

Answer A is incorrect because Password manager means software that securely stores and often generates unique credentials. That concept can be valid in another scenario, but this question is testing temporary elevation granted only when needed and removed automatically after a short period; Just-in-time permission therefore fits the requirement more directly.

Answer C is incorrect because Multifactor authentication means authentication using factors from more than one category such as knowledge, possession, or inherence. That concept can be valid in another scenario, but this question is testing temporary elevation granted only when needed and removed automatically after a short period; Just-in-time permission therefore fits the requirement more directly.

Answer D is incorrect because Attribute-based access control (ABAC) means an access model that evaluates attributes of users, resources, actions, and environment. That concept can be valid in another scenario, but this question is testing temporary elevation granted only when needed and removed automatically after a short period; Just-in-time permission therefore fits the requirement more directly.

 

Question 16

The team is resolving a gap found during an identity and privileged-access design review: it needs personal knowledge answer does not authenticate a physical authenticator or establish possession. Which option is most appropriate?

  1. An answer to a personal knowledge question
  2. A physical authenticator that establishes possession
  3. Least privilege
  4. LDAP

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A personal knowledge answer does not authenticate a physical authenticator or establish possession. That makes it the best answer here; LDAP addresses a protocol for querying and modifying directory services containing identities and related attributes, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because A biometric comparison must be combined with authentication of a physical authenticator. That concept can be valid in another scenario, but this question is testing A personal knowledge answer does not authenticate a physical authenticator or establish possession; An answer to a personal knowledge question therefore fits the requirement more directly.

Answer C is incorrect because Least privilege means the principle of granting only the access required to perform assigned duties. That concept can be valid in another scenario, but this question is testing A personal knowledge answer does not authenticate a physical authenticator or establish possession; An answer to a personal knowledge question therefore fits the requirement more directly.

Answer D is incorrect because LDAP means a protocol for querying and modifying directory services containing identities and related attributes. The concept is valid, but it does not match this stem. The required function is A personal knowledge answer does not authenticate a physical authenticator or establish possession, which maps to An answer to a personal knowledge question.

 

Question 17

During an identity and privileged-access design review, the team needs access model in which resource owners can grant or modify access permissions. Which option best meets this requirement?

  1. Federation
  2. A second biometric characteristic without a physical authenticator
  3. Security key
  4. Discretionary access control (DAC)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Discretionary access control (DAC) means an access model in which resource owners can grant or modify access permissions. This is the precise fit for the scenario. A second biometric characteristic without a physical authenticator serves the different purpose of Another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator.

Incorrect Answers

 

Answer A is incorrect because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. The question is not asking for this function. It is testing an access model in which resource owners can grant or modify access permissions, so Discretionary access control (DAC) is the stronger fit.

Answer B is incorrect because Another biometric characteristic is still an inherence factor and does not establish possession of a physical authenticator. The key mismatch is functional: Discretionary access control (DAC) addresses an access model in which resource owners can grant or modify access permissions, the need stated by the question.

Answer C is incorrect because Security key means a hardware authenticator that performs cryptographic challenge-response for supported authentication protocols. The concept is valid, but it does not match this stem. The required function is an access model in which resource owners can grant or modify access permissions, which maps to Discretionary access control (DAC).

 

Question 18

During an identity and privileged-access design review, the team needs removal or disabling of accounts and permissions when access is no longer required. Which option best meets this requirement?

  1. Identity proofing
  2. A physical authenticator that establishes possession
  3. Attestation
  4. User deprovisioning

Correct Answer: D

Correct Answer

 

 

Answer D is correct because User deprovisioning means removal or disabling of accounts and permissions when access is no longer required. This matches the requirement as written. A physical authenticator that establishes possession can be valid in another context, but it is used for A biometric comparison must be combined with authentication of a physical authenticator.

Incorrect Answers

 

Answer A is incorrect because Identity proofing means verification of a person’s real-world identity before issuing credentials or establishing an account. This could be appropriate elsewhere, but the required function is removal or disabling of accounts and permissions when access is no longer required; that makes User deprovisioning the precise choice.

Answer B is incorrect because A biometric comparison must be combined with authentication of a physical authenticator. The concept is valid, but it does not match this stem. The required function is removal or disabling of accounts and permissions when access is no longer required, which maps to User deprovisioning.

Answer C is incorrect because Attestation means formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid. That concept can be valid in another scenario, but this question is testing removal or disabling of accounts and permissions when access is no longer required; User deprovisioning therefore fits the requirement more directly.

 

Question 19

The team is resolving a gap found during an identity and privileged-access design review: it needs formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid. Which option is most appropriate?

  1. Federation
  2. LDAP
  3. Attestation
  4. Discretionary access control (DAC)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Attestation means formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid. That makes it the best answer here; Federation addresses trust arrangement that lets identities from one security domain access resources in another without separate local credentials, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. This could be appropriate elsewhere, but the required function is formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid; that makes Attestation the precise choice.

Answer B is incorrect because LDAP means a protocol for querying and modifying directory services containing identities and related attributes. The scenario instead requires formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid, which is why Attestation is the better answer; this option serves the different function defined above.

Answer D is incorrect because Discretionary access control (DAC) means an access model in which resource owners can grant or modify access permissions. The key mismatch is functional: Attestation addresses formal confirmation that an identity, device, access assignment, or security state has been reviewed and remains valid, the need stated by the question.

 

Question 20

The team is resolving a gap found during an identity and privileged-access design review: it needs hardware authenticator that performs cryptographic challenge-response for supported authentication protocols. Which option is most appropriate?

  1. Federation
  2. Security key
  3. LDAP
  4. Single sign-on (SSO)

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Security key means a hardware authenticator that performs cryptographic challenge-response for supported authentication protocols. That is the function the question is testing. Federation would instead be used for trust arrangement that lets identities from one security domain access resources in another without separate local credentials.

Incorrect Answers

 

Answer A is incorrect because Federation means trust arrangement that lets identities from one security domain access resources in another without separate local credentials. The question is not asking for this function. It is testing a hardware authenticator that performs cryptographic challenge-response for supported authentication protocols, so Security key is the stronger fit.

Answer C is incorrect because LDAP means a protocol for querying and modifying directory services containing identities and related attributes. The question is not asking for this function. It is testing a hardware authenticator that performs cryptographic challenge-response for supported authentication protocols, so Security key is the stronger fit.

Answer D is incorrect because Single sign-on (SSO) means authentication arrangement that lets a user authenticate once and access multiple integrated services. That concept can be valid in another scenario, but this question is testing a hardware authenticator that performs cryptographic challenge-response for supported authentication protocols; Security key therefore fits the requirement more directly.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!