Realistic Practice. AI Security. Adaptive Learning. Exam Readiness.
Aligned with the latest ISC2 CISSP Exam Outline
Practice across all eight CISSP domains
🟠No registration🔵 Instant Access 🟡 Works on Any Device
CISSP Domain 5 Master Cheat Sheet: Identity and Access Management (IAM)
Identity & Access Management (IAM) (13%)
Everything You Need to Remember for the CISSP Exam
1. Identity & Access Management Fundamentals
Identity and Access Management (IAM) ensures that the right individuals receive the right access to the right resources at the right time while preventing unauthorized access.
IAM Objectives
Objective | Purpose |
Identification | Claim an identity |
Authentication | Verify identity |
Authorization | Grant permissions |
Accountability | Track actions through logging |
Auditing | Review security events |
Non-Repudiation | Prevent denial of performed actions |
Remember
IAAA = Identify → Authenticate → Authorize → Audit
Core IAM Principles
Least Privilege
Need-to-Know
Separation of Duties
Job Rotation
Mandatory Vacation
Privileged Access Management (PAM)
Just-In-Time (JIT) Access
Zero Trust
Defense in Depth
Principle of Least Privilege
Users receive only the permissions necessary to perform their jobs.
Benefits
Smaller attack surface
Reduced insider risk
Better compliance
Limits malware propagation
Need-to-Know
Users may access information only when there is a legitimate business requirement.
Example
An HR employee cannot access Engineering design documents.
Separation of Duties (SoD)
Critical tasks are divided among multiple individuals.
Example
Developer writes code
↓
Security reviews code
↓
Administrator deploys code
Job Rotation
Rotating responsibilities helps detect fraud and reduces dependency on a single employee.
Mandatory Vacation
Extended leave often exposes fraudulent or malicious activities.
Privileged Access Management (PAM)
Protects highly privileged accounts.
Features
Password vaulting
Credential rotation
Session recording
Just-In-Time privileges
Approval workflows
Popular Solutions
CyberArk
Delinea
BeyondTrust
HashiCorp Vault
2. Identification & Authentication
Identification
A user claims an identity.
Examples
Username
Employee ID
Email address
Smart Card ID
Authentication Factors
Something You Know
Password
PIN
Passphrase
Something You Have
Smart card
Security token
Mobile authenticator
Hardware key (YubiKey)
Something You Are
Fingerprint
Iris
Retina
Facial recognition
Voice recognition
Somewhere You Are
GPS location
Corporate network
Something You Do
Typing rhythm
Signature dynamics
Mouse movement
Walking gait
Multifactor Authentication (MFA)
Uses two or more different authentication factors.
Examples
Password + Token
Password + Fingerprint
Smart Card + PIN
Authentication vs Authorization
Authentication | Authorization |
Verifies identity | Determines permissions |
Occurs first | Occurs after authentication |
Login process | Resource access |
Password Best Practices
Long passphrases
Password managers
MFA
Block compromised passwords
Adaptive authentication
Passwordless authentication
Password Attacks
Brute Force
Dictionary
Rainbow Tables
Credential Stuffing
Password Spraying
Keylogging
Authentication Protocols
Kerberos
Ticket-based
Uses Key Distribution Center (KDC)
Mutual authentication
LDAP
Directory services
Active Directory
RADIUS
Centralized authentication
Commonly used for VPNs
TACACS+
Cisco environments
Separates authentication, authorization and accounting
SAML
Federated identity
Web SSO
XML based
OAuth 2.0
Authorization framework
Delegated access
OpenID Connect (OIDC)
Authentication layer built on OAuth 2.0
JWT Tokens
Common in cloud applications
Single Sign-On (SSO)
Authenticate once
↓
Access multiple systems
Benefits
Better user experience
Fewer passwords
Reduced help desk calls
Risks
Single point of compromise
Federated Identity
Trust relationship between organizations.
Examples
Azure AD
Google Workspace
Okta
Ping Identity
Identity Proofing
Before an identity is created, organizations verify:
Government ID
Biometric verification
Background checks
HR validation
Identity Lifecycle
Join
↓
Provision
↓
Modify
↓
Suspend
↓
Deprovision
Provisioning
Automatically creates accounts.
Deprovisioning
Immediately removes access when users leave.
One of the highest-risk IAM failures tested on CISSP.
Identity Governance & Administration (IGA)
Provides
Identity lifecycle
Access reviews
Role management
Compliance reporting
Certification campaigns
Identity Repositories
Active Directory
Azure AD
LDAP
Cloud Identity Providers
Hybrid Identity Systems
Identity Federation Standards
Standard | Purpose |
SAML | Enterprise SSO |
OAuth 2.0 | Authorization |
OpenID Connect | Authentication |
SCIM | Automated provisioning |
LDAP | Directory services |
Kerberos | Ticket authentication |
Domain 5 Memory Aids
Topic | Memory Trick |
IAAA | Identify → Authenticate → Authorize → Audit |
Authentication Factors | Know • Have • Are • Do • Are (Location) |
AAA | Authentication • Authorization • Accounting |
IAM Lifecycle | Join → Move → Leave |
MFA | Two different factors |
SSO | One login, many systems |
Least Privilege | Minimum permissions |
SoD | Split critical duties |
Key Takeaways
Identity must be established before access is granted.
Authentication verifies identity; authorization determines permissions.
MFA significantly reduces account compromise.
PAM protects privileged accounts through vaulting, monitoring, and just-in-time access.
Identity lifecycle management (provisioning, modification, deprovisioning) is essential for secure operations.
Federation and SSO simplify user access while requiring strong trust relationships.
Access Control Models, Authorization & Identity Governance
3. Access Control Models
Access control determines who can access which resources and what actions they may perform. Understanding the differences between access control models is heavily tested on the CISSP exam.
Mandatory Access Control (MAC)
The system determines access based on security labels and classifications.
Characteristics
Centralized administration
Uses security labels
Highly secure
Users cannot modify permissions
Common in government and military environments
Example
Top Secret documents may only be accessed by individuals with a Top Secret clearance and a valid need-to-know.
Advantages
Strong confidentiality
Difficult for users to bypass
Excellent for classified environments
Disadvantages
Complex to administer
Less flexible
Discretionary Access Control (DAC)
The owner of an object controls who can access it.
Characteristics
Flexible
Owner manages permissions
Common in Windows and Linux file systems
Example
A user shares a folder and grants read access to coworkers.
Advantages
Easy to administer
Flexible
Disadvantages
Vulnerable to malware
Permissions may be granted improperly
Role-Based Access Control (RBAC)
Permissions are assigned to roles, and users inherit permissions through their assigned role.
Example
Role | Permissions |
HR Manager | Employee Records |
Accountant | Financial Systems |
Network Administrator | Network Devices |
Security Analyst | SIEM & Logs |
Benefits
Simplifies administration
Supports least privilege
Easy onboarding and offboarding
Attribute-Based Access Control (ABAC)
Access decisions are based on attributes.
User Attributes
Department
Clearance
Job title
Resource Attributes
Classification
Owner
Sensitivity
Environmental Attributes
Time of day
Location
Device type
Risk score
Example
Allow access only if:
Department = Finance
AND
Location = Corporate Network
AND
Time = Business Hours
AND
MFA = SuccessfulBenefits
Highly flexible
Dynamic access decisions
Common in cloud environments
Rule-Based Access Control
Access is determined by predefined rules.
Examples
Firewall rules
ACLs
Time-based restrictions
Network segmentation
Risk-Adaptive Access Control
Modern Zero Trust environments continuously evaluate risk.
Factors include
Device health
User behavior
Location
Threat intelligence
Impossible travel
Risk score
High risk may require
MFA
Step-up authentication
Session termination
Access denial
Comparing Access Control Models
Model | Access Controlled By | Best Use Case |
MAC | System | Military, Government |
DAC | Owner | Small organizations |
RBAC | Job Role | Enterprises |
ABAC | Attributes | Cloud & Zero Trust |
Rule-Based | Security Rules | Networks & Firewalls |
4. Authorization
Authorization determines what an authenticated user is permitted to do.
Examples
Read
Write
Execute
Delete
Modify
Create
Approve
Authorization Principles
Least Privilege
Grant only required permissions.
Need-to-Know
Only access information necessary for assigned duties.
Separation of Duties
Critical responsibilities are divided.
Example
Developer
↓
Code Reviewer
↓
Release Manager
Dual Control
Two authorized individuals must complete a sensitive task.
Examples
Launch nuclear systems
Access cryptographic keys
Bank vault access
Split Knowledge
No individual possesses the complete secret.
Common in
HSMs
Cryptographic key management
5. Access Control Mechanisms
Access Control Lists (ACL)
Specify permissions for individual users or groups.
Example
Finance Folder
Manager → Full Control
Analyst → Read
Intern → No AccessCapability Tables
Associate permissions with users rather than objects.
Group-Based Access
Permissions assigned through
Active Directory Groups
Azure AD Groups
LDAP Groups
Implicit Deny
Default action is
"Deny access unless explicitly permitted."
This is a CISSP favorite.
6. Account Management
Account Lifecycle
Hire
↓
Provision
↓
Modify
↓
Disable
↓
DeleteAccount Types
User Accounts
Normal daily users
Shared Accounts
Multiple users share credentials.
Generally discouraged because accountability is lost.
Service Accounts
Used by applications.
Should
Have strong passwords
Never be interactive
Be monitored
Rotate credentials regularly
Privileged Accounts
Examples
Domain Admin
Root
Enterprise Administrator
Cloud Global Administrator
Require
MFA
PAM
Session recording
Approval workflows
Emergency Accounts
"Break Glass Accounts"
Used only during emergencies.
Should
Be monitored
Be offline when possible
Require executive approval
7. Identity Governance & Administration (IGA)
IGA provides enterprise identity management.
Functions include
Identity lifecycle
Role mining
Access certification
Compliance reporting
Provisioning automation
Segregation of duties analysis
Popular platforms
SailPoint
Saviynt
Microsoft Entra ID Governance
8. Access Reviews & Certification
Managers periodically review user permissions.
Questions include
Does this employee still require access?
Has the employee changed roles?
Are privileged accounts still necessary?
Are orphaned accounts present?
Benefits
Reduces privilege creep
Improves compliance
Detects excessive permissions
9. Privilege Creep
Users gradually accumulate excessive permissions over time.
Example
Employee moves
Support
↓
Developer
↓
Manager
↓
Director
Old permissions remain active.
Solution
Regular access recertification.
10. Identity Analytics
Modern IAM platforms analyze
User behavior
Login patterns
Risk scores
Impossible travel
Privilege changes
Excessive permissions
This supports continuous identity monitoring.
11. Zero Trust Identity
Core Principle
Never Trust. Always Verify.
Characteristics
Continuous authentication
Continuous authorization
Device posture validation
Context-aware decisions
Least privilege
Microsegmentation
Adaptive MFA
CISSP Exam Tips
✔ Authentication occurs before authorization.
✔ Authorization defines what actions are permitted.
✔ RBAC simplifies administration in large enterprises.
✔ ABAC provides the greatest flexibility and is increasingly common in cloud-native environments.
✔ MAC offers the strongest confidentiality but the least flexibility.
✔ Privilege creep should be addressed through regular access reviews and certification campaigns.
✔ Implicit deny is the preferred default access control posture.
Domain 5 Memory Aids
Topic | Memory Trick |
Access Models | MDRAR → MAC • DAC • RBAC • ABAC • Rule-Based |
Authorization | Least Privilege Always Wins |
PAM | Vault • Rotate • Monitor • Record |
IGA | Govern • Certify • Provision |
Account Lifecycle | Join → Move → Leave |
Zero Trust | Never Trust. Always Verify. |
Implicit Deny | Deny Unless Allowed |
Key Takeaways
MAC, DAC, RBAC, and ABAC each solve different business problems.
Authorization controls what users can do after successful authentication.
RBAC is the enterprise standard, while ABAC dominates modern cloud and Zero Trust architectures.
IGA and PAM are essential for controlling identities and privileged access.
Regular access reviews prevent privilege creep and strengthen compliance.
The CISSP exam favors business-driven, least-privilege, risk-based authorization decisions over technical shortcuts.
Federation, Identity Infrastructure, Biometrics, Passwordless Authentication & Identity Attacks
12. Physical Access Controls
Physical access controls protect facilities, systems, personnel, and critical infrastructure from unauthorized physical access.
Preventive Controls
Security Guards
Fences
Bollards
Locks
Smart Cards
Biometrics
Security Lighting
Turnstiles
Mantraps
Badge Readers
Detective Controls
CCTV
Motion Sensors
IDS Alarms
Security Patrols
Door Position Sensors
Visitor Logs
Corrective Controls
Incident Response
Lock Replacement
Security Repairs
Badge Revocation
Deterrent Controls
Warning Signs
Uniformed Guards
Visible Cameras
Lighting
Recovery Controls
Backup Power
Alternate Facilities
Disaster Recovery Sites
Mantraps
A mantrap is a small controlled entry area with two interlocking doors that allows only one person (or one authorized group) to enter at a time.
Purpose
Prevent tailgating
Prevent piggybacking
Enforce identity verification
Turnstiles
Control one-person entry and reduce unauthorized access.
Commonly used in:
Office buildings
Stadiums
Data centers
Visitor Management
Best practices include:
Government-issued ID verification
Visitor badges
Escort requirements
Visitor logs
Badge expiration
Temporary credentials
13. Biometrics
Biometric authentication verifies identity using unique physical or behavioral characteristics.
Physiological Biometrics
Fingerprint
Palm Print
Iris
Retina
Face Recognition
Hand Geometry
Vein Pattern
Behavioral Biometrics
Typing Rhythm
Voice Recognition
Signature Dynamics
Mouse Movement
Gait Analysis
Biometric Performance Metrics
Metric | Meaning |
FAR | False Acceptance Rate |
FRR | False Rejection Rate |
CER | Crossover Error Rate |
EER | Equal Error Rate |
False Acceptance Rate (FAR)
Unauthorized users are incorrectly accepted.
Higher FAR = Lower Security
False Rejection Rate (FRR)
Authorized users are incorrectly rejected.
Higher FRR = Lower Usability
Crossover Error Rate (CER / EER)
The point where FAR equals FRR.
Lower CER indicates a better biometric system.
CISSP Tip
Lower CER = Better biometric accuracy.
Biometric Errors
Error | Description |
Type I Error | False Rejection |
Type II Error | False Acceptance |
Remember
Security prefers lower FAR.
Users prefer lower FRR.
14. Identity Proofing
Identity proofing establishes confidence that an identity belongs to a real individual.
Examples
Government-issued ID
Passport
Driver's License
HR Verification
Background Check
Video Verification
Registration Process
Typical lifecycle
Identity Proofing
↓
Identity Registration
↓
Credential Issuance
↓
Authentication
↓
Authorization
↓
Periodic Review
↓
Deprovisioning
15. Federated Identity Management
Federation enables users to access resources across organizations using trusted identity providers.
Examples
Azure AD
Microsoft Entra ID
Google Identity
Okta
Ping Identity
Benefits
Single identity
Fewer passwords
Simplified administration
Improved user experience
Better security
Identity Provider (IdP)
Authenticates users.
Examples
Azure AD
Okta
Google Workspace
Service Provider (SP)
Relies on the IdP to authenticate users.
Example
Salesforce trusts Azure AD.
Federation Standards
SAML (Security Assertion Markup Language)
Purpose
Enterprise Single Sign-On
Characteristics
XML-based
Browser authentication
Widely used in enterprises
Example
Azure AD
↓
Authenticates User
↓
User accesses Salesforce
OAuth 2.0
Purpose
Authorization delegation.
Allows applications to access resources without exposing passwords.
Example
"Login with Google"
OpenID Connect (OIDC)
Built on OAuth 2.0.
Provides authentication.
Most modern cloud applications use OIDC.
SCIM
System for Cross-domain Identity Management.
Purpose
Automated provisioning and deprovisioning.
Example
New employee
↓
HR System
↓
Azure AD
↓
Office 365
↓
Salesforce
↓
Slack
Automatically provisioned.
Comparing Federation Standards
Standard | Primary Purpose |
LDAP | Directory Services |
Kerberos | Authentication |
RADIUS | Network Authentication |
TACACS+ | Device Administration |
SAML | Enterprise SSO |
OAuth 2.0 | Authorization |
OpenID Connect | Authentication |
SCIM | Automated Provisioning |
16. Directory Services
LDAP
Lightweight Directory Access Protocol
Provides centralized directory information.
Stores
Users
Groups
Computers
Organizational Units (OUs)
Active Directory
Microsoft implementation of LDAP.
Supports
Kerberos
Group Policy
Single Sign-On
Centralized authentication
Kerberos
Ticket-based authentication protocol.
Components
Client
↓
Authentication Server (AS)
↓
Ticket Granting Server (TGS)
↓
Service Server
CISSP Remember
Kerberos requires synchronized clocks.
Default tolerance:
Approximately 5 minutes.
RADIUS
Remote Authentication Dial-In User Service.
Common uses
VPN
Wireless Networks
Remote Access
Characteristics
UDP
Combines authentication and authorization
TACACS+
Primarily Cisco environments.
Characteristics
TCP
Encrypts entire packet
Separates Authentication, Authorization and Accounting
LDAP vs Kerberos
LDAP | Kerberos |
Directory Service | Authentication Protocol |
Stores identities | Issues tickets |
User database | Identity verification |
17. Passwordless Authentication
Increasingly adopted by enterprises.
Technologies
Windows Hello
FIDO2
Passkeys
YubiKeys
Face Recognition
Fingerprint
TPM
Secure Enclave
Benefits
Eliminates password reuse
Stops phishing
Better user experience
Lower help desk costs
18. Identity Threats
Credential Stuffing
Uses stolen passwords from previous breaches.
Mitigation
MFA
Password Managers
Password Blacklists
Password Spraying
Attempts common passwords across many accounts.
Example
Spring2026!
Brute Force
Attempts every password combination.
Mitigation
Account lockout
MFA
Long passwords
Dictionary Attack
Uses common password lists.
Rainbow Tables
Attack precomputed password hashes.
Mitigation
Salt passwords.
Pass-the-Hash
Attacker authenticates using stolen password hashes.
Mitigation
Credential Guard
PAM
Least Privilege
Pass-the-Ticket
Kerberos ticket theft.
Mitigation
Short ticket lifetimes
Privileged Access Management
Monitoring
Golden Ticket
Attacker compromises the Kerberos Key Distribution Center (KDC) by forging Ticket Granting Tickets (TGTs).
Extremely severe.
Silver Ticket
Forged service ticket targeting a single service.
Kerberoasting
Requests Kerberos service tickets and performs offline password cracking.
Mitigation
Strong service account passwords
gMSA (Group Managed Service Accounts)
Monitor unusual TGS requests
Account Lockout
Common policy
Lock after 5 failed attempts
Temporary lockout
Progressive delays
Balances security and usability.
CISSP Exam Tips
✔ Authentication verifies identity.
✔ Authorization determines permissions.
✔ Federation enables trust between organizations.
✔ OAuth authorizes; OpenID Connect authenticates.
✔ SAML dominates enterprise SSO.
✔ Kerberos uses tickets and requires synchronized clocks.
✔ RADIUS is common for VPNs; TACACS+ is preferred for network device administration.
✔ Passwordless authentication and phishing-resistant MFA are becoming enterprise best practices.
✔ Lower CER means a better biometric system.
Domain 5 Memory Aids
Topic | Memory Trick |
Federation | SAML = SSO • OAuth = Authorization • OIDC = Authentication • SCIM = Provisioning |
Biometrics | Lower CER = Better |
Kerberos | Tickets + Time Synchronization |
LDAP | Stores identities |
PAM | Vault • Rotate • Monitor |
Pass-the-Hash | Hash stolen |
Kerberoasting | Crack service account tickets |
Passwordless | Passkeys defeat phishing |
Key Takeaways
Physical and logical access controls work together to secure organizational assets.
Biometrics improve authentication but must balance security (FAR) and usability (FRR).
Federation standards (SAML, OAuth 2.0, OIDC, and SCIM) underpin modern cloud identity management.
Kerberos, LDAP, RADIUS, and TACACS+ each serve distinct roles in enterprise authentication and authorization.
Passwordless authentication and phishing-resistant MFA represent the future of secure identity.
Understanding identity attacks and their mitigations is essential for both the CISSP exam and real-world IAM implementations.
Final Review, CISSP Questions & Exam Readiness
19. Common CISSP Domain 5 Exam Traps
Identity & Access Management is heavily tested through scenario-based questions. Many answers appear technically correct, but only one best aligns with business objectives, least privilege, and risk management.
Trap 1 – Authentication vs Authorization
This is one of the most common CISSP mistakes.
Authentication | Authorization |
Verifies identity | Determines permissions |
Login process | Resource access |
Happens first | Happens second |
Remember
Authenticate who you are.
Authorize what you can do.
Trap 2 – Confusing Identification with Authentication
Example
Employee enters username.
↓
Identification
Employee enters password.
↓
Authentication
Trap 3 – Selecting RBAC When ABAC Is Better
Many cloud questions favor ABAC because access decisions can include:
User attributes
Device health
Location
Time
Risk score
Department
RBAC remains excellent for traditional enterprises.
Trap 4 – Forgetting Least Privilege
The CISSP almost always favors:
✔ Least Privilege
✔ Need-to-Know
✔ Just-In-Time Access
✔ Zero Trust
over granting broad administrative access.
Trap 5 – Ignoring Identity Lifecycle
One of the biggest real-world risks:
Employee leaves
↓
Account never disabled
↓
Account compromised
Always remember:
Immediate deprovisioning.
20. Manager vs Engineer Mindset
The CISSP exam is testing whether you think like a Security Leader, not an identity administrator.
Engineer Thinking | CISSP Thinking |
Reset password | Improve IAM governance |
Grant Administrator rights | Apply Least Privilege |
Disable MFA for convenience | Reduce organizational risk |
Fix one account | Improve identity lifecycle |
Solve login problem | Improve IAM architecture |
Remember
Identity is now the primary security perimeter.
Modern organizations protect
Identity first.
21. Identity Governance Best Practices
Modern IAM programs include:
✔ Identity Proofing
✔ Strong Authentication
✔ MFA Everywhere
✔ Passwordless Authentication
✔ Privileged Access Management
✔ Identity Governance
✔ Continuous Monitoring
✔ Access Reviews
✔ Automated Provisioning
✔ Automated Deprovisioning
✔ Adaptive Authentication
✔ Risk-Based Authentication
22. Zero Trust Identity Principles
Traditional Security
Authenticate Once
↓
Trusted ForeverZero Trust
Authenticate
↓
Authorize
↓
Continuously Validate
↓
Monitor
↓
ReauthorizeCore Principles
Never Trust
Always Verify
Least Privilege
Assume Breach
Continuous Authentication
Device Validation
Risk-Based Decisions
23. Cloud Identity Best Practices
Modern cloud environments rely heavily on IAM.
Best practices
MFA
Conditional Access
Identity Federation
SCIM Provisioning
Least Privilege
Role-Based Access
Just-In-Time Administration
Privileged Identity Management (PIM)
Continuous Logging
Microsoft Entra ID / Azure AD
Common CISSP concepts include:
Conditional Access
Identity Protection
Privileged Identity Management (PIM)
Identity Governance
Access Reviews
24. Domain 5 Comparison Tables
Authentication Methods
Method | Security | Convenience |
Password | Low | High |
Passphrase | Medium | High |
Smart Card | High | Medium |
MFA | Very High | Medium |
Passkeys | Very High | Very High |
Biometrics | High | High |
Federation Standards
Standard | Primary Purpose |
LDAP | Directory |
Kerberos | Authentication |
SAML | Enterprise SSO |
OAuth 2.0 | Authorization |
OpenID Connect | Authentication |
SCIM | Provisioning |
Access Models
Model | Best Used For |
MAC | Military |
DAC | Small Organizations |
RBAC | Enterprises |
ABAC | Cloud & Zero Trust |
Rule-Based | Networks |
Authentication Factors
Factor | Example |
Know | Password |
Have | Smart Card |
Are | Fingerprint |
Do | Typing Pattern |
Are (Location) | GPS |
25. Final Domain 5 Revision Checklist
Before taking the CISSP exam, ensure you can confidently explain:
IAM Fundamentals
□ IAAA
□ AAA
□ Least Privilege
□ Need-to-Know
□ Separation of Duties
□ Job Rotation
□ Mandatory Vacation
Authentication
□ Passwords
□ MFA
□ Passwordless
□ Biometrics
□ Passkeys
Authorization
□ RBAC
□ ABAC
□ MAC
□ DAC
□ ACLs
Federation
□ SAML
□ OAuth 2.0
□ OpenID Connect
□ SCIM
Authentication Protocols
□ Kerberos
□ LDAP
□ RADIUS
□ TACACS+
Privileged Access
□ PAM


