5.0 Identity and Access Management (IAM) CISSP Practice Quiz

104 exam-style questions covering 13% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A regional bank is consolidating workforce identity after a merger and migrating users to a unified directory. A proposed access design creates risk around physical and logical access to assets. Which design change best addresses the concern?
  • A. Align physical and logical access controls with asset classification, business need, and risk tolerance
  • B. Treat a building badge as if it automatically conferred privileges in every application
  • C. Provision broadly permissive entitlements and depend on the SIEM to detect any abuse
  • D. Exempt machine identities from the joiner-mover-leaver process altogether

Access to assets should reflect the value and sensitivity of the asset and the business purpose for access. This is the correct answer.

A large public hospital is redesigning role-based access to electronic health records by clinical specialty. The CISO asks for CISSP-level guidance on physical and logical access to assets. Which approach is most appropriate?
  • A. Use separation between public, employee, privileged, and third-party access paths
  • B. Default new users to elevated rights and trust monitoring to surface inappropriate use
  • C. Exclude service principals from privileged access management coverage
  • D. Rely on a key-locked rack as the only protection for the domain controller console

Different populations create different risks and require distinct control models. This is the correct answer.

A defense contractor is auditing cleared-personnel access across classified and unclassified networks. Executives need a risk-based explanation for physical and logical access to assets. Which response best aligns with identity governance practice?
  • A. Use a single 'admin' account everyone shares for sensitive physical and logical entries
  • B. Use badge controls, visitor management, locks, cameras, and guards for physical access to sensitive facilities
  • C. Let physical entry into the data center auto-grant admin rights on the systems inside
  • D. Skip least-privilege at provisioning time and use detective controls to catch misuse

Physical access controls reduce unauthorized entry and create accountability around protected areas. This is the correct answer.

A federal civilian agency is implementing privileged access management to meet new oversight requirements. A security assurance review must address physical and logical access to assets. What should the security professional recommend?
  • A. Equate door-reader admittance with full logical authorization across enterprise systems
  • B. Protect privileged administrative interfaces with stronger authentication, monitoring, and limited access paths
  • C. Choose detective controls over preventive ones for new privileged provisioning
  • D. Treat non-human identities as out of scope for periodic recertification

Administrative access can change or bypass security controls and requires elevated protection. This is the correct answer.

A regional credit union is segmenting administrative access in response to a recent regulatory finding. An identity review identifies a weakness in physical and logical access to assets. Which action should be prioritized?
  • A. Use UEBA as a substitute for designing least-privilege roles in the first place
  • B. Remove shared physical or logical access mechanisms where individual accountability is required
  • C. Skip ownership assignment for service accounts so no one is accountable for them
  • D. Skip console authentication on a privileged jump box because the rack is locked

Shared access weakens attribution and complicates investigations. This is the correct answer.

A SaaS startup is rolling out customer identity federation to enterprise B2B partners. The security team must make an IAM decision involving physical and logical access to assets. What is the best recommendation?
  • A. Protect the privileged management console with only a locked equipment cabinet
  • B. Have all admins log into a common privileged account for both buildings and systems
  • C. Use network, application, database, and operating system controls to restrict logical access to information assets
  • D. Conflate having an office key with being authorized to approve financial transactions

Logical controls enforce who or what can access systems and data. This is the correct answer.

A municipal water utility is reconciling SCADA operator identities with corporate Active Directory. A proposed access design creates risk around physical and logical access to assets. Which design change best addresses the concern?
  • A. Standardize on a single shared 'manager' badge and login across all sensitive areas
  • B. Provision system entitlements based solely on which floor of the building a user can enter
  • C. Use access control matrices or policy models to map subjects, objects, and allowed operations
  • D. Provision wide access by default and treat alerting as the primary line of defense

Structured access mapping helps validate whether permissions match intended business rules. This is the correct answer.

A multinational pharmaceutical's CIO is restructuring access for clinical research and regulatory staff. An identity review identifies a weakness in physical and logical access to assets. Which action should be prioritized?
  • A. Skip access reviews for service accounts because they are 'just background jobs'
  • B. Treat the data center door as a sufficient compensating control for an unauthenticated console
  • C. Issue one shared root credential used by every administrator across facilities and apps
  • D. Apply need-to-know and least privilege across both physical facilities and logical systems

Users should receive only the access needed to perform authorized duties. This is the correct answer.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/isc2-cissp/identity-and-access-management/

<a href="https://quizbuffet.com/isc2-cissp/identity-and-access-management/">CISSP (ISC2) Identity and Access Management (IAM) practice quiz on QuizBuffet</a>

Other CISSP Domains

← Back to CISSP practice test overview

Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.