16 questions

Identity and Access Management (IAM)

An internal portal authenticates users with a password alone. Under NIST SP 800-63B-4, what is the minimum password length the verifier must require?

  • a.15 characters✓
  • b.12 characters
  • c.8 characters
  • d.64 characters

SP 800-63B-4 Section 3.1.1.2 requires passwords used as a single-factor authentication mechanism to be at least 15 characters; passwords used only as part of multi-factor authentication may be shorter but at least 8. Twelve characters is not a threshold in the guideline, and 64 is the maximum length verifiers should permit, not a minimum.

Identity and Access Management (IAM)

Under NIST SP 800-63B-4, when must a verifier force a user to change a password?

  • a.Every 90 days as a routine precaution
  • b.Whenever the user logs in from a new device
  • c.Each time the organization updates its policy
  • d.On evidence of compromise✓

SP 800-63B-4 states verifiers shall not require subscribers to change passwords periodically but shall force a change if there is evidence that the authenticator has been compromised. Scheduled rotation, a new device and a policy update are not evidence of compromise.

Identity and Access Management (IAM)

A security team proposes requiring at least one uppercase letter, one digit and one symbol in every password. How does NIST SP 800-63B-4 treat this proposal?

  • a.It requires them for all passwords
  • b.It recommends them for admin accounts
  • c.It forbids them and uses a blocklist instead✓
  • d.It allows them with 60-day expiry

SP 800-63B-4 states verifiers shall not impose composition rules such as requiring mixtures of character types, and instead has them compare prospective passwords against a blocklist of commonly used, expected or compromised values. The guideline has no administrator exception for composition rules and separately forbids periodic expiry.

Identity and Access Management (IAM)

Why does NIST SP 800-63B-4 not treat a six-digit code from an authenticator app as phishing-resistant?

  • a.The app stores its seed secret in plain text
  • b.The code is delivered over the telephone network
  • c.The six-digit code is too short to resist guessing
  • d.The typed code is not bound to the session✓

SP 800-63B-4 Section 3.2.5 states that authenticators involving manual entry of an output, such as OTP and out-of-band authenticators, shall not be considered phishing-resistant because the entry does not bind the output to the specific session, so an impostor verifier can relay it. Phishing resistance requires channel binding or verifier name binding, as with PIV/CAC client-authenticated TLS or WebAuthn. Code length, storage and PSTN delivery are separate issues.

Identity and Access Management (IAM)

Attackers who have an employee's password repeatedly trigger push-approval prompts until the employee taps 'Approve'. Which design change does NIST SP 800-63B-4 require for out-of-band authentication to counter this?

  • a.Show a list of codes and ask the user to pick one
  • b.Send the push prompt to a second phone number
  • c.Allow approval with a single tap but log each prompt
  • d.Require entry of a code shown on the other channel✓

SP 800-63B-4 notes that approve-only out-of-band methods are no longer acceptable because of 'authentication fatigue' attacks, and requires the secret to be transferred between the out-of-band device and the primary channel; it also says presenting a list of secrets to compare is insufficient because users can guess. Sending prompts elsewhere or logging them does not stop a fatigued user from approving.

Identity and Access Management (IAM)

A web application asks for a password and then for a PIN chosen by the user. How many authentication factors does this login use?

  • a.Two factors, because two secrets are entered
  • b.One, since both are something you know✓
  • c.Three factors, counting the username
  • d.Two factors, because the PIN is numeric

SP 800-63B-4 counts factors by category (something you know, something you have, something you are), so a password plus a PIN are both memorized secrets in the same category. Entering two secrets or using digits does not add a category, and a username is an identifier, not an authentication factor.

Identity and Access Management (IAM)

A calendar app wants to read a user's schedule from a cloud service without ever seeing the user's password. What does OAuth 2.0 provide for this?

  • a.A Kerberos ticket from the user's domain
  • b.An access token from an authorization server✓
  • c.A signed certificate of the user's identity
  • d.The user's password, shared securely

RFC 6749 describes OAuth 2.0 as letting a client obtain limited access to protected resources on behalf of the resource owner through an access token issued by the authorization server, instead of using the resource owner's credentials. Sharing the password is the anti-pattern OAuth replaces, and Kerberos tickets and user certificates are different authentication mechanisms.

Identity and Access Management (IAM)

Users in a Kerberos realm suddenly cannot obtain service tickets after a workstation's clock drifted by 20 minutes. Why does Kerberos depend on synchronized clocks?

  • a.The KDC issues tickets only during business hours
  • b.Tickets are encrypted with the current time as the key
  • c.Timestamps are checked to detect replays✓
  • d.Clock time is used as the user's password salt

RFC 4120 requires loosely synchronized clocks because authenticators include timestamps that the KDC and services check against an acceptable clock skew window to detect replayed messages. Tickets are encrypted with keys, not the time; there is no business-hours rule; and time is not a password salt.

Identity and Access Management (IAM)

A hospital needs a rule that nurses may view a patient record only while assigned to that patient's ward during their shift. Which access control model (ABAC, DAC, MAC or RBAC) expresses this most directly?

  • a.RBAC
  • b.DAC
  • c.MAC
  • d.ABAC✓

NIST SP 800-162 describes ABAC as evaluating attributes of the subject (role, ward assignment), the object (patient location) and the environment (time of shift) against policy. Discretionary access control (DAC) leaves the decision to the resource owner, mandatory access control (MAC) compares fixed labels with clearances, and role-based access control (RBAC) alone grants by role without conditions such as current ward or time.

Identity and Access Management (IAM)

On a classified system, a document's owner tries to grant a colleague access, but the system refuses because the colleague's clearance does not match the document's label. Which access control model is in force?

  • a.Mandatory access control (MAC)✓
  • b.Risk-based access control
  • c.Rule-based access control
  • d.Discretionary access control (DAC)

RFC 4949 defines mandatory access control as comparing security labels with clearances, and explains it is 'mandatory' because an entity cannot, by its own volition, enable another entity to access the resource. Under discretionary access control the owner could grant access at will, and rule-based and risk-based controls evaluate rules or risk signals rather than labels versus clearances.

Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Identity and Access Management (IAM)

An employee moved from accounts payable to treasury last year and still holds payables permissions. Which practice would have caught this?

  • a.Enabling full-disk encryption on the laptop
  • b.Reviewing access when staff transfer✓
  • c.Adding the employee to the incident response team
  • d.Requiring a longer password after the move

NIST SP 800-53 Rev. 5 AC-2 requires notifying account managers when users are transferred, periodic account reviews, and aligning account management with transfer processes, and PS-5 requires reviewing the ongoing need for existing access on reassignment. Password length, disk encryption and team membership do not remove unneeded permissions.

Identity and Access Management (IAM)

An application uses a service account to connect to a database. Which practice best manages this account?

  • a.Share its password with the developers who might need it
  • b.Give it domain administrator rights to avoid failures
  • c.Exempt it from access reviews because no person uses it
  • d.An owner, no interactive login, vaulted rotated secret✓

The ISC2 outline lists service account management within the provisioning lifecycle, and NIST SP 800-53 Rev. 5 AC-2 applies account management, including defined account types, account managers and periodic review, to service accounts as well. Sharing its password, granting excessive rights or exempting it from review turns a non-human account into an unmonitored path to the data.

Identity and Access Management (IAM)

Linux administrators use sudo to run privileged commands. Which control does NIST SP 800-53 Rev. 5 specify so that misuse can be detected afterwards?

  • a.Share one root password among admins
  • b.Log the execution of privileged functions✓
  • c.Give administrators direct root logins
  • d.Rotate administrators between teams

SP 800-53 Rev. 5 control enhancement AC-6(9) requires logging the execution of privileged functions, which gives an audit trail of what each administrator ran through sudo. A shared root password or direct root logins destroy individual accountability, and rotating staff between teams does not record what anyone did.

Identity and Access Management (IAM)

A domain administrator reads email and browses the web while logged in with the administrator account. Which control addresses this?

  • a.A separate non-privileged account for other tasks✓
  • b.Grant the account wider rights so tasks never fail
  • c.Allow the browser to store the administrator password
  • d.Give the administrator a faster workstation

NIST SP 800-53 Rev. 5 AC-6(2) requires users with privileged accounts to use non-privileged accounts when accessing non-security functions, so phishing or a malicious site does not run with administrator rights. Hardware speed is irrelevant, saving the password in a browser widens exposure, and wider rights increase the damage.

Identity and Access Management (IAM)

Under NIST SP 800-63B-4, what is the maximum overall reauthentication timeout for a session at authenticator assurance level 3 (AAL3)?

  • a.12 hours✓
  • b.30 days
  • c.15 minutes
  • d.24 hours

SP 800-63B-4 Section 2.3.3 states that at AAL3 the overall timeout for reauthentication shall be no more than 12 hours. The guideline's summary table recommends 24 hours overall at AAL2 and 30 days at AAL1, and 15 minutes is the recommended AAL3 inactivity timeout rather than the overall limit.

Identity and Access Management (IAM)

A user's valid login arrives from a country the user has never visited, at 3 a.m. local time, from an unmanaged device. The system demands an extra authentication step before granting access. What type of access control is this?

  • a.Risk-based access control✓
  • b.Discretionary access control
  • c.Role-based access control
  • d.Mandatory access control

The ISC2 outline lists risk-based access control among authorization mechanisms, and NIST SP 800-207 describes access determined by dynamic policy that can include behavioral and environmental attributes such as location, time and device state. Discretionary, mandatory and role-based controls grant access from ownership, labels or roles without adjusting to real-time risk signals.

Report