5.0 Identity and Access Management (IAM) CISSP Practice Quiz
104 exam-style questions covering 13% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A regional bank is consolidating workforce identity after a merger and migrating users to a unified directory. A proposed access design creates risk around physical and logical access to assets. Which design change best addresses the concern?
- A. Align physical and logical access controls with asset classification, business need, and risk tolerance
- B. Treat a building badge as if it automatically conferred privileges in every application
- C. Provision broadly permissive entitlements and depend on the SIEM to detect any abuse
- D. Exempt machine identities from the joiner-mover-leaver process altogether
Access to assets should reflect the value and sensitivity of the asset and the business purpose for access. This is the correct answer.
A large public hospital is redesigning role-based access to electronic health records by clinical specialty. The CISO asks for CISSP-level guidance on physical and logical access to assets. Which approach is most appropriate?
- A. Use separation between public, employee, privileged, and third-party access paths
- B. Default new users to elevated rights and trust monitoring to surface inappropriate use
- C. Exclude service principals from privileged access management coverage
- D. Rely on a key-locked rack as the only protection for the domain controller console
Different populations create different risks and require distinct control models. This is the correct answer.
A defense contractor is auditing cleared-personnel access across classified and unclassified networks. Executives need a risk-based explanation for physical and logical access to assets. Which response best aligns with identity governance practice?
- A. Use a single 'admin' account everyone shares for sensitive physical and logical entries
- B. Use badge controls, visitor management, locks, cameras, and guards for physical access to sensitive facilities
- C. Let physical entry into the data center auto-grant admin rights on the systems inside
- D. Skip least-privilege at provisioning time and use detective controls to catch misuse
Physical access controls reduce unauthorized entry and create accountability around protected areas. This is the correct answer.
A federal civilian agency is implementing privileged access management to meet new oversight requirements. A security assurance review must address physical and logical access to assets. What should the security professional recommend?
- A. Equate door-reader admittance with full logical authorization across enterprise systems
- B. Protect privileged administrative interfaces with stronger authentication, monitoring, and limited access paths
- C. Choose detective controls over preventive ones for new privileged provisioning
- D. Treat non-human identities as out of scope for periodic recertification
Administrative access can change or bypass security controls and requires elevated protection. This is the correct answer.
A regional credit union is segmenting administrative access in response to a recent regulatory finding. An identity review identifies a weakness in physical and logical access to assets. Which action should be prioritized?
- A. Use UEBA as a substitute for designing least-privilege roles in the first place
- B. Remove shared physical or logical access mechanisms where individual accountability is required
- C. Skip ownership assignment for service accounts so no one is accountable for them
- D. Skip console authentication on a privileged jump box because the rack is locked
Shared access weakens attribution and complicates investigations. This is the correct answer.
A SaaS startup is rolling out customer identity federation to enterprise B2B partners. The security team must make an IAM decision involving physical and logical access to assets. What is the best recommendation?
- A. Protect the privileged management console with only a locked equipment cabinet
- B. Have all admins log into a common privileged account for both buildings and systems
- C. Use network, application, database, and operating system controls to restrict logical access to information assets
- D. Conflate having an office key with being authorized to approve financial transactions
Logical controls enforce who or what can access systems and data. This is the correct answer.
A municipal water utility is reconciling SCADA operator identities with corporate Active Directory. A proposed access design creates risk around physical and logical access to assets. Which design change best addresses the concern?
- A. Standardize on a single shared 'manager' badge and login across all sensitive areas
- B. Provision system entitlements based solely on which floor of the building a user can enter
- C. Use access control matrices or policy models to map subjects, objects, and allowed operations
- D. Provision wide access by default and treat alerting as the primary line of defense
Structured access mapping helps validate whether permissions match intended business rules. This is the correct answer.
A multinational pharmaceutical's CIO is restructuring access for clinical research and regulatory staff. An identity review identifies a weakness in physical and logical access to assets. Which action should be prioritized?
- A. Skip access reviews for service accounts because they are 'just background jobs'
- B. Treat the data center door as a sufficient compensating control for an unauthenticated console
- C. Issue one shared root credential used by every administrator across facilities and apps
- D. Apply need-to-know and least privilege across both physical facilities and logical systems
Users should receive only the access needed to perform authorized duties. This is the correct answer.
Key Terms in This Domain
- FIM: Federated Identity Management: trust across organizations/domains
- NIST Risk Management Framework: NIST SP 800-37 lifecycle for managing information system risk
- Zero Trust: Never trust, always verify: continuous authentication and authorization
- VLAN: Logical L2 segmentation within a physical network
- NAC: Network Access Control: endpoint posture/identity check at admission
- Identification: Claiming an identity (username)
- Authentication: Proving the claimed identity (password, token, biometric)
- Authorization: Determining what an authenticated identity may do
- SSO: Single Sign-On: one authentication for multiple systems
- OAuth 2.0: Authorization framework for delegated access (access tokens)
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/identity-and-access-management/
<a href="https://quizbuffet.com/isc2-cissp/identity-and-access-management/">CISSP (ISC2) Identity and Access Management (IAM) practice quiz on QuizBuffet</a>
Other CISSP Domains
- 1.0 Security and Risk Management
- 2.0 Asset Security
- 3.0 Security Architecture and Engineering
- 4.0 Communication and Network Security
- 6.0 Security Assessment and Testing
- 7.0 Security Operations
- 8.0 Software Development Security
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.