Test your Identity and Access Management knowledge with a free interactive quiz — 26 questions with answers and explanations. No signup needed to play.
Question 1/12Score 0
A team needs a service to read from one specific database and write to one specific queue, nothing else. Which policy design best follows IAM best practice?
In this round
A team needs a service to read from one specific database and write to one specific queue, nothing else. Which policy design best follows IAM best practice?
A company relies entirely on a manual offboarding checklist that an IT admin fills out for each departing employee. What risk does this create compared to an automated deprovisioning process?
Why is least privilege described as "a process, not a one-time setup"?
What are the three stages of the identity lifecycle commonly referred to as "joiner, mover, leaver"?
In AWS IAM, if one attached policy grants `s3:*` broadly and a second attached policy includes an explicit `Deny` on that same action for other resources, which one wins?
How does Attribute-Based Access Control (ABAC) differ fundamentally from RBAC?
Why should a cloud account's root/owner credentials be reserved for account recovery rather than day-to-day work?
How does OAuth 2.0 differ from OIDC in what it is designed to do?
Why is IAM described as more than "just a login system"?
What is the difference between authentication and authorization?
What does Single Sign-On (SSO) allow a user to do?
What two questions does an IAM system answer for every access request?
Gaps to close?
Read the curated Identity and Access Management notes — core concepts, patterns, interview prep.