Study. uk . com
  1. Home
  2. All questions
  3. Identity

CISSP study material: Identity

36 questions of the 500 in the CISSP — Certified Information Systems Security Professional quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 23. An engineer is building the access flow for a zero trust architecture. A contractor signs in with MFA from a laptop the enterprise has never seen and requests a session to an internal application. Which sequencing matches the SP 800-207 model?
  2. 43. A contractor is choosing authenticators for a system that must operate at Authentication Assurance Level 3 (AAL3) under NIST SP 800-63B-4. The security architect proposes passkeys synchronised across each staff member's phone and laptop through a cloud account. Why does this proposal fail the AAL3 requirement?
  3. 44. A credential service provider proofs applicants remotely at Identity Assurance Level 2 (IAL2), collecting one fair and one strong piece of evidence. A government customer now requires Identity Assurance Level 3 (IAL3), and the provider's analyst assumes the gap is stronger documents. Under NIST SP 800-63A-4, what actually distinguishes IAL3 proofing?
  4. 45. A bank is adding face recognition as an authentication factor. Testing shows the algorithm performs worse for one demographic group, so the vendor offers to lower the match threshold for that group so acceptance rates even out. Under NIST SP 800-63B-4, how should the bank respond to the offer?
  5. 46. A security manager is rewriting the password policy for a workforce portal to align with NIST SP 800-63B-4. The current policy mandates a mix of upper case, digits and symbols, expires every password after 90 days, and screens new passwords against a blocklist of breached values. Which two changes bring the policy into line? Choose two.
  6. 47. An agency runs a case-management system at Authentication Assurance Level 3 (AAL3). Analysts complain about being signed out during long reviews and ask to inherit the timings used by the intranet, which runs at Authentication Assurance Level 2 (AAL2). Under NIST SP 800-63B-4, which session limits must the case-management system keep?
  7. 48. A brokerage federates staff logins to an external identity provider. The risk team's worry is a breach of that provider itself: an attacker who controls it could mint assertions naming any employee. Which federation assurance level 3 (FAL3) requirement addresses that specific worry?
  8. 49. Two research institutes agree to federate under the SP 800-63C-4 federation guidance. They share no common public key infrastructure and neither will join the other's, yet their architects want federation assurance level 3 (FAL3) for a jointly funded data programme. Which binding approach suits this deployment?
  9. 50. A SaaS provider follows the SP 800-63C-4 back-channel presentation model between its identity provider and several relying parties. To cut load, its gateway caches each assertion reference and lets any registered relying party redeem it for up to an hour. Which change aligns the design with that model?
  10. 309. A RADIUS deployment is reviewed for how it protects the exchange between the network access server and the RADIUS server. Which two properties does RFC 2865 describe? Choose two.
  11. 311. A RADIUS server answers an Access-Request with an Access-Challenge. Which three things does the client include when it resubmits? Choose three.
  12. 312. A team proposes meeting a phishing-resistance requirement by mandating 20-character passwords. What does NIST SP 800-63B say?
  13. 313. A device requires a six-digit PIN to unlock a hardware authenticator, and an auditor objects that six digits breaches the password length rules. Why does that objection fail?
  14. 314. A verifier rejects any password containing a substring found on its blocklist, so that a passphrase containing a common word is refused. What does NIST SP 800-63B actually require?
  15. 315. A blocklist is being assembled for a new service. Which three sources does NIST SP 800-63B suggest it draw on? Choose three.
  16. 316. A service rejects a blocklisted password with a generic failure message and no further help. Which two things does NIST SP 800-63B require or recommend instead? Choose two.
  17. 317. A security team wants to expand its password blocklist to hundreds of millions of entries for extra safety. What does NIST SP 800-63B say about very large blocklists?
  18. 318. Which three password handling behaviours does NIST SP 800-63B recommend of verifiers? Choose three.
  19. 319. A sign-up flow lets users store a password hint shown on the login page, and asks for a memorable childhood question as a recovery method. Which two rules of NIST SP 800-63B does this breach? Choose two.
  20. 320. A legacy banking portal asks for the third, fifth and ninth characters of a customer's password, and silently ignores anything beyond 20 characters. Which two requirements of NIST SP 800-63B does this violate? Choose two.
  21. 321. A login page disables pasting into the password field to discourage credential sharing. What does NIST SP 800-63B say?
  22. 322. A design team debates whether offering to reveal the password as it is typed weakens security. What does NIST SP 800-63B recommend?
  23. 323. A verifier trims leading and trailing whitespace from submitted passwords before checking them. Under what condition does NIST SP 800-63B permit such allowances?
  24. 324. An engineer proposes storing passwords as a single unsalted SHA-256 digest for speed. Which two properties does NIST SP 800-63B require of stored passwords instead? Choose two.
  25. 325. A password hashing cost factor was chosen in 2018 and has never changed. What does NIST SP 800-63B recommend?
  26. 326. A password store keeps only the hash of each password, with a fixed application-wide salt and no record of the scheme used. Which three requirements or recommendations of NIST SP 800-63B are missed? Choose three.
  27. 327. A verifier adds a keyed hashing step using a secret only it holds. Where does NIST SP 800-63B say that key should live, and what does the step achieve?
  28. 328. A service issues each user a printed sheet of one-time codes for use if their phone is lost. In NIST SP 800-63B terms, what is this authenticator, and which factor does it represent?
  29. 329. Which two requirements does NIST SP 800-63B place on the generation and form of look-up secrets? Choose two.
  30. 330. A provider plans to deliver a new set of recovery codes through the user's existing web session. What does NIST SP 800-63B require of that session?
  31. 331. A consumer service authenticating at AAL1 asks how long a session may run before reauthentication, and whether an inactivity timeout is compulsory. What does NIST SP 800-63B say?
  32. 332. An AAL2 session has passed its inactivity timeout but not its overall timeout. What lighter reauthentication does NIST SP 800-63B permit?
  33. 333. How do AAL3 reauthentication requirements differ from those at AAL2?
  34. 334. Which three properties must an AAL3 authenticator and its protocol have, according to NIST SP 800-63B? Choose three.
  35. 335. A team assumes an out-of-band authenticator must meet stricter technical requirements when used at AAL2 than at AAL1. What does NIST SP 800-63B say?
  36. 336. A verifier sends a code to the subscriber's registered mobile device, which the subscriber then enters into the browser session being authenticated. Which authenticator type is this, in NIST SP 800-63B terms?