top of page

CISSP Domain 5 Master Cheat Sheet: Identity and Access Management (IAM)



Identity & Access Management (IAM) (13%)

Everything You Need to Remember for the CISSP Exam


1. Identity & Access Management Fundamentals

Identity and Access Management (IAM) ensures that the right individuals receive the right access to the right resources at the right time while preventing unauthorized access.


IAM Objectives

Objective

Purpose

Identification

Claim an identity

Authentication

Verify identity

Authorization

Grant permissions

Accountability

Track actions through logging

Auditing

Review security events

Non-Repudiation

Prevent denial of performed actions


Remember

IAAA = Identify → Authenticate → Authorize → Audit


Core IAM Principles

  • Least Privilege

  • Need-to-Know

  • Separation of Duties

  • Job Rotation

  • Mandatory Vacation

  • Privileged Access Management (PAM)

  • Just-In-Time (JIT) Access

  • Zero Trust

  • Defense in Depth


Principle of Least Privilege

Users receive only the permissions necessary to perform their jobs.

Benefits

  • Smaller attack surface

  • Reduced insider risk

  • Better compliance

  • Limits malware propagation


Need-to-Know

Users may access information only when there is a legitimate business requirement.

Example

An HR employee cannot access Engineering design documents.


Separation of Duties (SoD)

Critical tasks are divided among multiple individuals.

Example

Developer writes code

Security reviews code

Administrator deploys code


Job Rotation

Rotating responsibilities helps detect fraud and reduces dependency on a single employee.


Mandatory Vacation

Extended leave often exposes fraudulent or malicious activities.


Privileged Access Management (PAM)

Protects highly privileged accounts.

Features

  • Password vaulting

  • Credential rotation

  • Session recording

  • Just-In-Time privileges

  • Approval workflows


Popular Solutions

  • CyberArk

  • Delinea

  • BeyondTrust

  • HashiCorp Vault


2. Identification & Authentication

Identification

A user claims an identity.

Examples

Username

Employee ID

Email address

Smart Card ID


Authentication Factors

Something You Know

  • Password

  • PIN

  • Passphrase

Something You Have

  • Smart card

  • Security token

  • Mobile authenticator

  • Hardware key (YubiKey)

Something You Are

  • Fingerprint

  • Iris

  • Retina

  • Facial recognition

  • Voice recognition

Somewhere You Are

  • GPS location

  • Corporate network

Something You Do

  • Typing rhythm

  • Signature dynamics

  • Mouse movement

  • Walking gait


Multifactor Authentication (MFA)

Uses two or more different authentication factors.

Examples

Password + Token

Password + Fingerprint

Smart Card + PIN


Authentication vs Authorization

Authentication

Authorization

Verifies identity

Determines permissions

Occurs first

Occurs after authentication

Login process

Resource access


Password Best Practices

  • Long passphrases

  • Password managers

  • MFA

  • Block compromised passwords

  • Adaptive authentication

  • Passwordless authentication


Password Attacks

  • Brute Force

  • Dictionary

  • Rainbow Tables

  • Credential Stuffing

  • Password Spraying

  • Keylogging


Authentication Protocols

Kerberos

  • Ticket-based

  • Uses Key Distribution Center (KDC)

  • Mutual authentication


LDAP

Directory services

Active Directory


RADIUS

Centralized authentication

Commonly used for VPNs


TACACS+

Cisco environments

Separates authentication, authorization and accounting


SAML

Federated identity

Web SSO

XML based

OAuth 2.0


Authorization framework

Delegated access

OpenID Connect (OIDC)

Authentication layer built on OAuth 2.0

JWT Tokens

Common in cloud applications


Single Sign-On (SSO)

Authenticate once

Access multiple systems

Benefits

  • Better user experience

  • Fewer passwords

  • Reduced help desk calls

Risks

  • Single point of compromise


Federated Identity

Trust relationship between organizations.

Examples

Azure AD

Google Workspace

Okta

Ping Identity


Identity Proofing

Before an identity is created, organizations verify:

Government ID

Biometric verification

Background checks

HR validation


Identity Lifecycle

Join

Provision

Modify

Suspend

Deprovision


Provisioning

Automatically creates accounts.


Deprovisioning

Immediately removes access when users leave.

One of the highest-risk IAM failures tested on CISSP.


Identity Governance & Administration (IGA)

Provides

Identity lifecycle

Access reviews

Role management

Compliance reporting

Certification campaigns


Identity Repositories

Active Directory

Azure AD

LDAP

Cloud Identity Providers

Hybrid Identity Systems


Identity Federation Standards

Standard

Purpose

SAML

Enterprise SSO

OAuth 2.0

Authorization

OpenID Connect

Authentication

SCIM

Automated provisioning

LDAP

Directory services

Kerberos

Ticket authentication


Domain 5 Memory Aids

Topic

Memory Trick

IAAA

Identify → Authenticate → Authorize → Audit

Authentication Factors

Know • Have • Are • Do • Are (Location)

AAA

Authentication • Authorization • Accounting

IAM Lifecycle

Join → Move → Leave

MFA

Two different factors

SSO

One login, many systems

Least Privilege

Minimum permissions

SoD

Split critical duties


Key Takeaways

  • Identity must be established before access is granted.

  • Authentication verifies identity; authorization determines permissions.

  • MFA significantly reduces account compromise.

  • PAM protects privileged accounts through vaulting, monitoring, and just-in-time access.

  • Identity lifecycle management (provisioning, modification, deprovisioning) is essential for secure operations.

  • Federation and SSO simplify user access while requiring strong trust relationships.


Access Control Models, Authorization & Identity Governance


3. Access Control Models

Access control determines who can access which resources and what actions they may perform. Understanding the differences between access control models is heavily tested on the CISSP exam.


Mandatory Access Control (MAC)

The system determines access based on security labels and classifications.


Characteristics

  • Centralized administration

  • Uses security labels

  • Highly secure

  • Users cannot modify permissions

  • Common in government and military environments


Example

Top Secret documents may only be accessed by individuals with a Top Secret clearance and a valid need-to-know.


Advantages

  • Strong confidentiality

  • Difficult for users to bypass

  • Excellent for classified environments


Disadvantages

  • Complex to administer

  • Less flexible


Discretionary Access Control (DAC)

The owner of an object controls who can access it.


Characteristics

  • Flexible

  • Owner manages permissions

  • Common in Windows and Linux file systems


Example

A user shares a folder and grants read access to coworkers.


Advantages

  • Easy to administer

  • Flexible


Disadvantages

  • Vulnerable to malware

  • Permissions may be granted improperly


Role-Based Access Control (RBAC)

Permissions are assigned to roles, and users inherit permissions through their assigned role.

Example

Role

Permissions

HR Manager

Employee Records

Accountant

Financial Systems

Network Administrator

Network Devices

Security Analyst

SIEM & Logs


Benefits

  • Simplifies administration

  • Supports least privilege

  • Easy onboarding and offboarding


Attribute-Based Access Control (ABAC)

Access decisions are based on attributes.


User Attributes

  • Department

  • Clearance

  • Job title


Resource Attributes

  • Classification

  • Owner

  • Sensitivity


Environmental Attributes

  • Time of day

  • Location

  • Device type

  • Risk score


Example

Allow access only if:

Department = Finance

AND

Location = Corporate Network

AND

Time = Business Hours

AND

MFA = Successful

Benefits

  • Highly flexible

  • Dynamic access decisions

  • Common in cloud environments


Rule-Based Access Control

Access is determined by predefined rules.

Examples

  • Firewall rules

  • ACLs

  • Time-based restrictions

  • Network segmentation


Risk-Adaptive Access Control

Modern Zero Trust environments continuously evaluate risk.

Factors include

  • Device health

  • User behavior

  • Location

  • Threat intelligence

  • Impossible travel

  • Risk score

High risk may require

  • MFA

  • Step-up authentication

  • Session termination

  • Access denial


Comparing Access Control Models

Model

Access Controlled By

Best Use Case

MAC

System

Military, Government

DAC

Owner

Small organizations

RBAC

Job Role

Enterprises

ABAC

Attributes

Cloud & Zero Trust

Rule-Based

Security Rules

Networks & Firewalls


4. Authorization

Authorization determines what an authenticated user is permitted to do.

Examples

  • Read

  • Write

  • Execute

  • Delete

  • Modify

  • Create

  • Approve


Authorization Principles

Least Privilege

Grant only required permissions.

Need-to-Know

Only access information necessary for assigned duties.

Separation of Duties

Critical responsibilities are divided.

Example

Developer

Code Reviewer

Release Manager

Dual Control

Two authorized individuals must complete a sensitive task.

Examples

  • Launch nuclear systems

  • Access cryptographic keys

  • Bank vault access

Split Knowledge

No individual possesses the complete secret.

Common in

  • HSMs

  • Cryptographic key management


5. Access Control Mechanisms

Access Control Lists (ACL)

Specify permissions for individual users or groups.

Example

Finance Folder

Manager → Full Control

Analyst → Read

Intern → No Access

Capability Tables

Associate permissions with users rather than objects.


Group-Based Access

Permissions assigned through

  • Active Directory Groups

  • Azure AD Groups

  • LDAP Groups


Implicit Deny

Default action is

"Deny access unless explicitly permitted."

This is a CISSP favorite.


6. Account Management

Account Lifecycle

Hire

↓

Provision

↓

Modify

↓

Disable

↓

Delete

Account Types

User Accounts

Normal daily users

Shared Accounts

Multiple users share credentials.

Generally discouraged because accountability is lost.

Service Accounts

Used by applications.

Should

  • Have strong passwords

  • Never be interactive

  • Be monitored

  • Rotate credentials regularly

Privileged Accounts

Examples

  • Domain Admin

  • Root

  • Enterprise Administrator

  • Cloud Global Administrator

Require

  • MFA

  • PAM

  • Session recording

  • Approval workflows

Emergency Accounts

"Break Glass Accounts"

Used only during emergencies.

Should

  • Be monitored

  • Be offline when possible

  • Require executive approval


7. Identity Governance & Administration (IGA)

IGA provides enterprise identity management.

Functions include

  • Identity lifecycle

  • Role mining

  • Access certification

  • Compliance reporting

  • Provisioning automation

  • Segregation of duties analysis


Popular platforms

  • SailPoint

  • Saviynt

  • Microsoft Entra ID Governance


8. Access Reviews & Certification

Managers periodically review user permissions.


Questions include

  • Does this employee still require access?

  • Has the employee changed roles?

  • Are privileged accounts still necessary?

  • Are orphaned accounts present?


Benefits

  • Reduces privilege creep

  • Improves compliance

  • Detects excessive permissions


9. Privilege Creep

Users gradually accumulate excessive permissions over time.

Example

Employee moves

Support

Developer

Manager

Director

Old permissions remain active.

Solution

Regular access recertification.


10. Identity Analytics

Modern IAM platforms analyze

  • User behavior

  • Login patterns

  • Risk scores

  • Impossible travel

  • Privilege changes

  • Excessive permissions

This supports continuous identity monitoring.


11. Zero Trust Identity

Core Principle

Never Trust. Always Verify.

Characteristics

  • Continuous authentication

  • Continuous authorization

  • Device posture validation

  • Context-aware decisions

  • Least privilege

  • Microsegmentation

  • Adaptive MFA


CISSP Exam Tips

✔ Authentication occurs before authorization.

✔ Authorization defines what actions are permitted.

✔ RBAC simplifies administration in large enterprises.

✔ ABAC provides the greatest flexibility and is increasingly common in cloud-native environments.

✔ MAC offers the strongest confidentiality but the least flexibility.

✔ Privilege creep should be addressed through regular access reviews and certification campaigns.

✔ Implicit deny is the preferred default access control posture.


Domain 5 Memory Aids

Topic

Memory Trick

Access Models

MDRAR → MAC • DAC • RBAC • ABAC • Rule-Based

Authorization

Least Privilege Always Wins

PAM

Vault • Rotate • Monitor • Record

IGA

Govern • Certify • Provision

Account Lifecycle

Join → Move → Leave

Zero Trust

Never Trust. Always Verify.

Implicit Deny

Deny Unless Allowed


Key Takeaways

  • MAC, DAC, RBAC, and ABAC each solve different business problems.

  • Authorization controls what users can do after successful authentication.

  • RBAC is the enterprise standard, while ABAC dominates modern cloud and Zero Trust architectures.

  • IGA and PAM are essential for controlling identities and privileged access.

  • Regular access reviews prevent privilege creep and strengthen compliance.

  • The CISSP exam favors business-driven, least-privilege, risk-based authorization decisions over technical shortcuts.


Federation, Identity Infrastructure, Biometrics, Passwordless Authentication & Identity Attacks


12. Physical Access Controls

Physical access controls protect facilities, systems, personnel, and critical infrastructure from unauthorized physical access.


Preventive Controls

  • Security Guards

  • Fences

  • Bollards

  • Locks

  • Smart Cards

  • Biometrics

  • Security Lighting

  • Turnstiles

  • Mantraps

  • Badge Readers


Detective Controls

  • CCTV

  • Motion Sensors

  • IDS Alarms

  • Security Patrols

  • Door Position Sensors

  • Visitor Logs


Corrective Controls

  • Incident Response

  • Lock Replacement

  • Security Repairs

  • Badge Revocation


Deterrent Controls

  • Warning Signs

  • Uniformed Guards

  • Visible Cameras

  • Lighting


Recovery Controls

  • Backup Power

  • Alternate Facilities

  • Disaster Recovery Sites


Mantraps

A mantrap is a small controlled entry area with two interlocking doors that allows only one person (or one authorized group) to enter at a time.


Purpose

  • Prevent tailgating

  • Prevent piggybacking

  • Enforce identity verification


Turnstiles

Control one-person entry and reduce unauthorized access.

Commonly used in:

  • Office buildings

  • Stadiums

  • Data centers


Visitor Management

Best practices include:

  • Government-issued ID verification

  • Visitor badges

  • Escort requirements

  • Visitor logs

  • Badge expiration

  • Temporary credentials


13. Biometrics

Biometric authentication verifies identity using unique physical or behavioral characteristics.


Physiological Biometrics

  • Fingerprint

  • Palm Print

  • Iris

  • Retina

  • Face Recognition

  • Hand Geometry

  • Vein Pattern


Behavioral Biometrics

  • Typing Rhythm

  • Voice Recognition

  • Signature Dynamics

  • Mouse Movement

  • Gait Analysis


Biometric Performance Metrics

Metric

Meaning

FAR

False Acceptance Rate

FRR

False Rejection Rate

CER

Crossover Error Rate

EER

Equal Error Rate


False Acceptance Rate (FAR)

Unauthorized users are incorrectly accepted.

Higher FAR = Lower Security


False Rejection Rate (FRR)

Authorized users are incorrectly rejected.

Higher FRR = Lower Usability


Crossover Error Rate (CER / EER)

The point where FAR equals FRR.

Lower CER indicates a better biometric system.


CISSP Tip

Lower CER = Better biometric accuracy.


Biometric Errors

Error

Description

Type I Error

False Rejection

Type II Error

False Acceptance

Remember

Security prefers lower FAR.

Users prefer lower FRR.


14. Identity Proofing

Identity proofing establishes confidence that an identity belongs to a real individual.

Examples

  • Government-issued ID

  • Passport

  • Driver's License

  • HR Verification

  • Background Check

  • Video Verification


Registration Process

Typical lifecycle

Identity Proofing

Identity Registration

Credential Issuance

Authentication

Authorization

Periodic Review

Deprovisioning


15. Federated Identity Management

Federation enables users to access resources across organizations using trusted identity providers.

Examples

  • Azure AD

  • Microsoft Entra ID

  • Google Identity

  • Okta

  • Ping Identity


Benefits

  • Single identity

  • Fewer passwords

  • Simplified administration

  • Improved user experience

  • Better security


Identity Provider (IdP)

Authenticates users.

Examples

  • Azure AD

  • Okta

  • Google Workspace


Service Provider (SP)

Relies on the IdP to authenticate users.

Example

Salesforce trusts Azure AD.


Federation Standards

SAML (Security Assertion Markup Language)

Purpose

Enterprise Single Sign-On

Characteristics

  • XML-based

  • Browser authentication

  • Widely used in enterprises

Example

Azure AD

Authenticates User

User accesses Salesforce


OAuth 2.0

Purpose

Authorization delegation.

Allows applications to access resources without exposing passwords.

Example

"Login with Google"


OpenID Connect (OIDC)

Built on OAuth 2.0.

Provides authentication.

Most modern cloud applications use OIDC.


SCIM

System for Cross-domain Identity Management.

Purpose

Automated provisioning and deprovisioning.

Example

New employee

HR System

Azure AD

Office 365

Salesforce

Slack

Automatically provisioned.


Comparing Federation Standards

Standard

Primary Purpose

LDAP

Directory Services

Kerberos

Authentication

RADIUS

Network Authentication

TACACS+

Device Administration

SAML

Enterprise SSO

OAuth 2.0

Authorization

OpenID Connect

Authentication

SCIM

Automated Provisioning


16. Directory Services

LDAP

Lightweight Directory Access Protocol

Provides centralized directory information.

Stores

  • Users

  • Groups

  • Computers

  • Organizational Units (OUs)


Active Directory

Microsoft implementation of LDAP.

Supports

  • Kerberos

  • Group Policy

  • Single Sign-On

  • Centralized authentication


Kerberos

Ticket-based authentication protocol.

Components

Client

Authentication Server (AS)

Ticket Granting Server (TGS)

Service Server


CISSP Remember

Kerberos requires synchronized clocks.

Default tolerance:

Approximately 5 minutes.


RADIUS

Remote Authentication Dial-In User Service.

Common uses

  • VPN

  • Wireless Networks

  • Remote Access

Characteristics

  • UDP

  • Combines authentication and authorization


TACACS+

Primarily Cisco environments.

Characteristics

  • TCP

  • Encrypts entire packet

  • Separates Authentication, Authorization and Accounting


LDAP vs Kerberos

LDAP

Kerberos

Directory Service

Authentication Protocol

Stores identities

Issues tickets

User database

Identity verification


17. Passwordless Authentication

Increasingly adopted by enterprises.

Technologies

  • Windows Hello

  • FIDO2

  • Passkeys

  • YubiKeys

  • Face Recognition

  • Fingerprint

  • TPM

  • Secure Enclave


Benefits

  • Eliminates password reuse

  • Stops phishing

  • Better user experience

  • Lower help desk costs


18. Identity Threats

Credential Stuffing

Uses stolen passwords from previous breaches.

Mitigation

  • MFA

  • Password Managers

  • Password Blacklists


Password Spraying

Attempts common passwords across many accounts.

Example

Spring2026!


Brute Force

Attempts every password combination.

Mitigation

  • Account lockout

  • MFA

  • Long passwords


Dictionary Attack

Uses common password lists.


Rainbow Tables

Attack precomputed password hashes.

Mitigation

Salt passwords.


Pass-the-Hash

Attacker authenticates using stolen password hashes.

Mitigation

  • Credential Guard

  • PAM

  • Least Privilege


Pass-the-Ticket

Kerberos ticket theft.

Mitigation

  • Short ticket lifetimes

  • Privileged Access Management

  • Monitoring


Golden Ticket

Attacker compromises the Kerberos Key Distribution Center (KDC) by forging Ticket Granting Tickets (TGTs).

Extremely severe.


Silver Ticket

Forged service ticket targeting a single service.


Kerberoasting

Requests Kerberos service tickets and performs offline password cracking.

Mitigation

  • Strong service account passwords

  • gMSA (Group Managed Service Accounts)

  • Monitor unusual TGS requests


Account Lockout

Common policy

  • Lock after 5 failed attempts

  • Temporary lockout

  • Progressive delays

Balances security and usability.


CISSP Exam Tips

✔ Authentication verifies identity.

✔ Authorization determines permissions.

✔ Federation enables trust between organizations.

✔ OAuth authorizes; OpenID Connect authenticates.

✔ SAML dominates enterprise SSO.

✔ Kerberos uses tickets and requires synchronized clocks.

✔ RADIUS is common for VPNs; TACACS+ is preferred for network device administration.

✔ Passwordless authentication and phishing-resistant MFA are becoming enterprise best practices.

✔ Lower CER means a better biometric system.


Domain 5 Memory Aids

Topic

Memory Trick

Federation

SAML = SSO • OAuth = Authorization • OIDC = Authentication • SCIM = Provisioning

Biometrics

Lower CER = Better

Kerberos

Tickets + Time Synchronization

LDAP

Stores identities

PAM

Vault • Rotate • Monitor

Pass-the-Hash

Hash stolen

Kerberoasting

Crack service account tickets

Passwordless

Passkeys defeat phishing


Key Takeaways

  • Physical and logical access controls work together to secure organizational assets.

  • Biometrics improve authentication but must balance security (FAR) and usability (FRR).

  • Federation standards (SAML, OAuth 2.0, OIDC, and SCIM) underpin modern cloud identity management.

  • Kerberos, LDAP, RADIUS, and TACACS+ each serve distinct roles in enterprise authentication and authorization.

  • Passwordless authentication and phishing-resistant MFA represent the future of secure identity.

  • Understanding identity attacks and their mitigations is essential for both the CISSP exam and real-world IAM implementations.


Final Review, CISSP Questions & Exam Readiness


19. Common CISSP Domain 5 Exam Traps

Identity & Access Management is heavily tested through scenario-based questions. Many answers appear technically correct, but only one best aligns with business objectives, least privilege, and risk management.


Trap 1 – Authentication vs Authorization

This is one of the most common CISSP mistakes.

Authentication

Authorization

Verifies identity

Determines permissions

Login process

Resource access

Happens first

Happens second


Remember

Authenticate who you are.
Authorize what you can do.

Trap 2 – Confusing Identification with Authentication

Example

Employee enters username.

Identification

Employee enters password.

Authentication


Trap 3 – Selecting RBAC When ABAC Is Better

Many cloud questions favor ABAC because access decisions can include:

  • User attributes

  • Device health

  • Location

  • Time

  • Risk score

  • Department

RBAC remains excellent for traditional enterprises.


Trap 4 – Forgetting Least Privilege

The CISSP almost always favors:

✔ Least Privilege

✔ Need-to-Know

✔ Just-In-Time Access

✔ Zero Trust

over granting broad administrative access.


Trap 5 – Ignoring Identity Lifecycle

One of the biggest real-world risks:

Employee leaves

Account never disabled

Account compromised

Always remember:

Immediate deprovisioning.


20. Manager vs Engineer Mindset

The CISSP exam is testing whether you think like a Security Leader, not an identity administrator.

Engineer Thinking

CISSP Thinking

Reset password

Improve IAM governance

Grant Administrator rights

Apply Least Privilege

Disable MFA for convenience

Reduce organizational risk

Fix one account

Improve identity lifecycle

Solve login problem

Improve IAM architecture


Remember

Identity is now the primary security perimeter.

Modern organizations protect

Identity first.


21. Identity Governance Best Practices

Modern IAM programs include:

✔ Identity Proofing

✔ Strong Authentication

✔ MFA Everywhere

✔ Passwordless Authentication

✔ Privileged Access Management

✔ Identity Governance

✔ Continuous Monitoring

✔ Access Reviews

✔ Automated Provisioning

✔ Automated Deprovisioning

✔ Adaptive Authentication

✔ Risk-Based Authentication


22. Zero Trust Identity Principles

Traditional Security

Authenticate Once

↓

Trusted Forever

Zero Trust

Authenticate

↓

Authorize

↓

Continuously Validate

↓

Monitor

↓

Reauthorize

Core Principles

  • Never Trust

  • Always Verify

  • Least Privilege

  • Assume Breach

  • Continuous Authentication

  • Device Validation

  • Risk-Based Decisions


23. Cloud Identity Best Practices

Modern cloud environments rely heavily on IAM.

Best practices

  • MFA

  • Conditional Access

  • Identity Federation

  • SCIM Provisioning

  • Least Privilege

  • Role-Based Access

  • Just-In-Time Administration

  • Privileged Identity Management (PIM)

  • Continuous Logging


Microsoft Entra ID / Azure AD

Common CISSP concepts include:

  • Conditional Access

  • Identity Protection

  • Privileged Identity Management (PIM)

  • Identity Governance

  • Access Reviews


24. Domain 5 Comparison Tables

Authentication Methods

Method

Security

Convenience

Password

Low

High

Passphrase

Medium

High

Smart Card

High

Medium

MFA

Very High

Medium

Passkeys

Very High

Very High

Biometrics

High

High


Federation Standards

Standard

Primary Purpose

LDAP

Directory

Kerberos

Authentication

SAML

Enterprise SSO

OAuth 2.0

Authorization

OpenID Connect

Authentication

SCIM

Provisioning


Access Models

Model

Best Used For

MAC

Military

DAC

Small Organizations

RBAC

Enterprises

ABAC

Cloud & Zero Trust

Rule-Based

Networks



Authentication Factors

Factor

Example

Know

Password

Have

Smart Card

Are

Fingerprint

Do

Typing Pattern

Are (Location)

GPS


25. Final Domain 5 Revision Checklist

Before taking the CISSP exam, ensure you can confidently explain:


IAM Fundamentals

□ IAAA

□ AAA

□ Least Privilege

□ Need-to-Know

□ Separation of Duties

□ Job Rotation

□ Mandatory Vacation


Authentication

□ Passwords

□ MFA

□ Passwordless

□ Biometrics

□ Passkeys


Authorization

□ RBAC

□ ABAC

□ MAC

□ DAC

□ ACLs


Federation

□ SAML

□ OAuth 2.0

□ OpenID Connect

□ SCIM


Authentication Protocols

□ Kerberos

□ LDAP

□ RADIUS

□ TACACS+


Privileged Access

□ PAM

□ PIM

□ Break Glass Accounts

□ Service Accounts


Identity Governance

□ IGA

□ Access Reviews

□ Provisioning

□ Deprovisioning

□ Privilege Creep


Identity Threats

□ Pass-the-Hash

□ Pass-the-Ticket

□ Kerberoasting

□ Credential Stuffing

□ Password Spraying


26. CISSP Domain 5 Memory Aids

Topic

Memory Trick

IAAA

Identify → Authenticate → Authorize → Audit

Authentication Factors

Know • Have • Are • Do • Location

Access Models

MDRAB → MAC • DAC • RBAC • ABAC • Rule-Based

Federation

SAML = SSO • OAuth = Authorization • OIDC = Authentication • SCIM = Provisioning

Biometrics

Lower CER = Better

PAM

Vault • Rotate • Monitor

Kerberos

Tickets + Time Synchronization

Zero Trust

Never Trust. Always Verify.

Identity Lifecycle

Join → Move → Leave


27. 10 CISSP-Style Practice Questions

Question 1

A security administrator is designing access controls for a military organization where access decisions are based on security classifications and clearances. Which access control model is MOST appropriate?

A. DAC

B. RBAC

C. ABAC

D. MAC

✅ Answer: D

Explanation

Mandatory Access Control (MAC) uses centrally managed security labels and is the preferred model for government and military environments.


Question 2

A company wants employees to use their corporate identity to access multiple SaaS applications without repeatedly logging in. Which technology BEST meets this requirement?

A. Kerberos

B. LDAP

C. SAML

D. FTP

✅ Answer: C

Explanation

SAML provides enterprise Single Sign-On (SSO) through federation between an Identity Provider (IdP) and Service Providers (SPs).


Question 3

Which authentication factor is represented by a fingerprint?

A. Something you know

B. Something you have

C. Something you are

D. Somewhere you are

✅ Answer: C

Explanation

Biometric characteristics such as fingerprints, iris scans, and facial recognition are examples of "something you are."


Question 4

A user authenticates successfully but is denied access to a financial application because they are not a member of the Finance role. Which IAM function prevented access?

A. Identification

B. Authentication

C. Authorization

D. Federation

✅ Answer: C

Explanation

Authorization determines what resources an authenticated user may access.


Question 5

An organization wants to reduce the risk of administrators having standing privileged access. Which solution BEST addresses this requirement?

A. Shared administrator accounts

B. Just-In-Time (JIT) Privileged Access

C. Disable MFA

D. Longer passwords

✅ Answer: B

Explanation

JIT access grants administrative privileges only when required and for a limited time, significantly reducing exposure.


Question 6

Which federation standard is specifically designed for automated user provisioning and deprovisioning?

A. LDAP

B. Kerberos

C. SCIM

D. OAuth 2.0

✅ Answer: C

Explanation

SCIM automates identity lifecycle management across cloud services and enterprise applications.


Question 7

A security team wants access decisions to consider a user's department, device compliance, geographic location, and time of day. Which access control model BEST fits this requirement?

A. DAC

B. RBAC

C. ABAC

D. MAC

✅ Answer: C

Explanation

ABAC evaluates multiple user, resource, and environmental attributes, making it ideal for dynamic and context-aware authorization.


Question 8

Which metric indicates the overall accuracy of a biometric authentication system?

A. FAR

B. FRR

C. CER (EER)

D. MFA

✅ Answer: C

Explanation

The Crossover Error Rate (CER), also called Equal Error Rate (EER), is where the False Acceptance Rate equals the False Rejection Rate. Lower values indicate better biometric performance.


Question 9

A former employee's account remains active for several weeks after termination and is later used in an unauthorized access attempt. Which IAM process failed?

A. Identity proofing

B. Authorization

C. Deprovisioning

D. Federation

✅ Answer: C

Explanation

Timely deprovisioning is essential to remove access immediately when employment ends.


Question 10

A cloud application allows users to sign in with their corporate identity while the application trusts the organization's Identity Provider (IdP). What security concept is being used?

A. DAC

B. Identity Federation

C. Password Spraying

D. Port Security

✅ Answer: B

Explanation

Identity Federation establishes trust between an Identity Provider and a Service Provider, enabling secure Single Sign-On.


28. Key Takeaways

  • Identity has become the new security perimeter in modern enterprises.

  • Effective IAM combines strong authentication, least privilege, authorization, governance, and continuous monitoring.

  • RBAC simplifies administration, while ABAC enables dynamic, context-aware access decisions for cloud and Zero Trust environments.

  • Federation technologies such as SAML, OAuth 2.0, OpenID Connect, and SCIM are foundational to modern identity ecosystems.

  • Privileged Access Management (PAM), Identity Governance (IGA), and timely deprovisioning are essential for reducing organizational risk.

  • Successful CISSP candidates evaluate IAM decisions from a business, governance, and risk management perspective—not just a technical one.


29. Related CISSP Articles

Expand your IAM knowledge with these in-depth GoCyberNinja guides:

  • Authentication vs. Authorization

  • Identity & Access Management (IAM)

  • Least Privilege

  • Zero Trust Architecture

  • Security Controls

  • Security Governance

  • Risk Management

  • Privileged Access Management (PAM)

  • Multi-Factor Authentication (MFA)

  • Passwordless Authentication

  • Security Awareness

  • Defense in Depth


Final Thoughts

Identity & Access Management is one of the most important domains in modern cybersecurity because nearly every security decision begins with verifying identity and controlling access. Whether securing on-premises systems, cloud platforms, or hybrid environments, strong IAM practices reduce risk, improve compliance, and support business objectives.

For the CISSP exam, remember that the best answers consistently emphasize least privilege, governance, continuous verification, and business-aligned risk management. Think like a security architect and trusted advisor—not just a system administrator—and you'll be well prepared for both the exam and real-world leadership roles.


GoCyberNinja Master Cheat Sheet Series

Maintain a consistent naming convention across all eight domains to reinforce your brand and improve discoverability:


Continue Your CISSP Journey with GoCyberNinja

Reading about secure software development is only the beginning. The CISSP exam evaluates your ability to apply security principles, assess business risk, and make informed management decisions across the entire software lifecycle.

GoCyberNinja CISSP Exam Prep helps reinforce Domain 8 through realistic, scenario-driven practice designed to build both technical understanding and executive-level decision-making.


Strengthen Your Domain 8 Knowledge

✅ Realistic CISSP Practice Questions covering all eight CISSP domains

✅ 1,200 Full Mock Exam Questions across eight comprehensive practice exams

✅ 400+ Scenario-Based Questions designed to develop the CISSP manager's mindset

✅ 1,040+ Flashcards for rapid review and long-term retention

✅ Adaptive Smart Review that automatically focuses on your weakest topics

✅ Performance Analytics to measure readiness and identify knowledge gaps

✅ Personalized Study Plans based on your learning progress

✅ Three Free CISSP Readiness Tests to benchmark your preparation before attempting full-length exams


Practice. Analyze. Master.

The CISSP is not a programming exam—it is a security leadership and risk management exam. Success comes from understanding how secure software supports business objectives, protects organizational assets, and reduces enterprise risk.

With GoCyberNinja CISSP Exam Prep, you'll build the judgment, confidence, and practical decision-making skills expected of a CISSP professional.

Practice smarter. Analyze deeper. Master the CISSP.


Take the FREE CISSP Readiness Tests to evaluate your knowledge, identify weak areas, and receive a personalized study roadmap before tackling the full question bank.

bottom of page