certslothcertsloth
CISSP/Topic 06

ISC2 / Professional

Identity, Authentication and Privileged Access

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Who are you, what may you do, and for how long?

Must remember

Factors are something you know, have or are. Two passwords are not MFA. Hardware-backed phishing-resistant authentication reduces risks that a phishable one-time code does not fully address. Biometrics need fallback and privacy controls; false acceptance and false rejection trade off against each other.

SSO reduces repeated sign-ins; federation lets one identity provider assert identity to another service. SAML carries assertions commonly used in enterprise federation. OAuth delegates authorization; OpenID Connect adds an identity layer. Kerberos uses tickets and depends on appropriate time synchronization. LDAP is a directory-access protocol, not encryption by itself.

RBAC grants access through roles; ABAC evaluates attributes and context; discretionary access lets owners delegate; mandatory access enforces centrally controlled labels. Least privilege restricts permissions; separation of duties prevents one person completing a sensitive workflow alone. Need-to-know narrows access even among sufficiently cleared users.

Provisioning must cover joiners, movers and leavers. Reconcile access after role changes and promptly revoke accounts, sessions, keys and tokens when required. Periodic access reviews find accumulated privilege and dormant accounts. Service accounts need ownership, scoped permissions and credential lifecycle controls too.

PAM manages privileged access with vaulting, approval, session recording and just-in-time elevation. Just-enough access narrows the permitted actions. A break-glass account needs controlled storage, monitoring and periodic tests; it should not become a daily shared login.

RADIUS commonly centralizes network access authentication; TACACS+ is often used for network-device administration with separable AAA functions. Certificates and device posture can supplement user identity. An authenticated user can still be compromised or unauthorized for the requested object.

Choose under exam pressure

Requirement Choice and reason
Temporary production administration Approved just-in-time privilege with logging.
Access depends on classification and device state Attribute/context-based policy.
A user changes department Reconcile old and new permissions, not only add the new role.

Traps

  • SSO without careful controls can concentrate compromise risk.
  • Authentication success does not establish authorization for every resource.

Active recall

1. Are password plus PIN two factors?

No; both are knowledge factors.

2. OAuth versus OIDC?

OAuth delegates authorization; OIDC adds standardized identity information.

3. What prevents permanent admin standing privilege?

Just-in-time elevation with approval, expiry and audit.

4. Why review movers?

They can accumulate unnecessary access from previous roles.

5. Why protect service-account lifecycle?

Nonhuman identities can retain powerful permissions and long-lived credentials without an obvious human owner.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.