Test your Identity and Access Management knowledge with a free interactive quiz — 26 questions with answers and explanations. No signup needed to play.
Question 1/12Score 0
What is "federation" in the context of SSO?
In this round
What is "federation" in the context of SSO?
In AWS IAM, if one attached policy grants `s3:*` broadly and a second attached policy includes an explicit `Deny` on that same action for other resources, which one wins?
What does Single Sign-On (SSO) allow a user to do?
How does Role-Based Access Control (RBAC) grant permissions?
Why should a cloud account's root/owner credentials be reserved for account recovery rather than day-to-day work?
What is the recommended way to grant a group of users the same set of cloud permissions, rather than attaching policies to each user individually?
Why is least privilege described as "a process, not a one-time setup"?
What is the primary security value of SSO beyond user convenience?
What is a common trade-off of adopting ABAC over RBAC?
What does SCIM (System for Cross-domain Identity Management) automate?
What does the principle of least privilege state?
Why is deprovisioning the identity lifecycle stage most associated with real-world security incidents?
Gaps to close?
Read the curated Identity and Access Management notes — core concepts, patterns, interview prep.