Identity and Access Management - CompTIA Security+ SY0-701 - 4.6

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/14

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:05 AM on 4/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

15 Terms

1
New cards

Identity and Access Management (IAM)

Application are available anywhere

- Desktop, browser, mobile device, etc

Data can be located anywhere

- Cloud storage, private data centers, etc

Many different application users

- Employees, vendors, contractors, customers

Give the right permissions to the right people at the right time

- Prevent unauthorized access

2
New cards

Identity and Access Management Cont

Identity lifecycle management

- Every entity (human and non-human) gets a digital identity

Access control

- An entity only gets access to what they need

Authentication and authorization

- Entities must prove they are who they claim to be

Identity governance

- Track an entity's resource access

- May be a regulatory requirement

3
New cards

Provisionsing/de-provisioning user accounts

The user account creation process

- And the account removal process

Provisioning and de-provisioning occurs for certain events

- Hiring, transfers, promotions, job separation

Account details

- Name, attributes, group permissions, other permissions

An important part of the IAM process

- An initial checkpoint to limit access

- Nobody gets Administrator access

4
New cards

Permission assignments

Each entity gets limited permissions

- Just enough to do their job

- Group assignments are common

Storage and files can be private to that user

- Even if another person is using the same computer

No privileged access to the operating system

- Specifically not allowed on a user account

5
New cards

Identity Proofing

• I could be anyone

- The IAM process should confirm who I am

• Resolution

- Who the system thinks you are

• Validation

- Gathering information from the user

(password, security questions, etc.)

• Verification / Attestation

- Passport, in-person meeting, etc.

- Automated verification is also an option

6
New cards

Gaining access

knowt flashcard image
7
New cards

Single Sign On (SSO)

• Provide credentials one time

- Get access to all available or assigned resources

- No additional authentication required

• Usually limited by time

- A single authentication can work for 24 hours

- Authenticate again after the timer expires

• The underlying authentication infrastructure must

support SSO

- Not always an option

8
New cards

LDAP (Lightweight Directory Access Protocol)

Protocol for reading and writing directories

• An organized set of records, like a phone directory

• X.500 specification was written by the International

Telecommunications Union (ITU)

• DAP ran on the OSI protocol stack

• LDAP is lightweight, and uses TCP/IP (tcp/389 and

udp/389)

• LDAP is the protocol used to query and update an

X.500 directory

• Used in Windows Active Directory, Apple

OpenDirectory, Novell eDirectory, etc.

9
New cards

X.500 Distinguished Names

Attribute= Value Pairs

Most specific attribute is listed first

- This may be similar to the way you already think

CN=WIDGETWEB, OU= Marketing, O=Widget, L=London, ST= London, C= GB, DC = Widget, DC=com

10
New cards

X.500 Directory Information Tree

Hierarchical Structure

- Builds a tree

Container objects

- Country, organizaiton, organizational units

<p>Hierarchical Structure</p><p>- Builds a tree</p><p>Container objects</p><p>- Country, organizaiton, organizational units</p>
11
New cards

Security Assertion Markup Language (SAML)

Open standard for authentication and authorization

- You can authenticate through a 3rd party to gain access

- One standard does it all, sort of

Not originally designed for mobile apps

- This has been SAML's largest roadblock

12
New cards

The SAML authentication flow

Identity provider (idp) = provides authentication

Sp = service provider for user/principal.

Rp = relying party leverages idp to provide authentication services

<p>Identity provider (idp) = provides authentication</p><p>Sp = service provider for user/principal.</p><p>Rp = relying party leverages idp to provide authentication services</p>
13
New cards

OAuth

Authorization framework

- Determines what resources a user will be able to access

Created by Twitter, Google, and many others

- Significant industry support

Not an authentication protocol

- OpenID Connect handles the single sign-on authentication

- OAuth provides authroization between applications

14
New cards

Federation

Provide network access to others

- Not just employees - Partners, suppliers, customers, etc

- Provides SSO and more

3rd party can establish a federated network

- Authenticate and authorize between the two organizations

- Login with your Facebook credentials

The 3rd party must establish a trust relationship

- And the degree of the trust

15
New cards

Interoperability

Many different ways to communicate with an authentication server

- More than a simple login process

Often determined by what is at hand

- VPN concentrator can talk to a LDAP server

- We have an LDAP server

A new app uses OAuth

- Need to allow authentication API access

The ineroperability is dependent on the environment

Explore top notes

note
Chapter 13: Acids and Bases
Updated 1090d ago
0.0(0)
note
Rocks
Updated 1040d ago
0.0(0)
note
Synaptic Transfer
Updated 1318d ago
0.0(0)
note
Property Recap
Updated 699d ago
0.0(0)
note
BI206L Lab Exam #2 Study Guide
Updated 592d ago
0.0(0)
note
Chapter 13: Acids and Bases
Updated 1090d ago
0.0(0)
note
Rocks
Updated 1040d ago
0.0(0)
note
Synaptic Transfer
Updated 1318d ago
0.0(0)
note
Property Recap
Updated 699d ago
0.0(0)
note
BI206L Lab Exam #2 Study Guide
Updated 592d ago
0.0(0)

Explore top flashcards

flashcards
Unit 4 vocabulary
55
Updated 1155d ago
0.0(0)
flashcards
NUR-111: Unit 1
90
Updated 440d ago
0.0(0)
flashcards
LOTF Vocabulary List #2
20
Updated 154d ago
0.0(0)
flashcards
Biosci 221 Exam 3
68
Updated 1064d ago
0.0(0)
flashcards
Wijsbegeerte begrippen deel III
40
Updated 823d ago
0.0(0)
flashcards
biology review: test 1
67
Updated 951d ago
0.0(0)
flashcards
William Billiam exam 4
22
Updated 206d ago
0.0(0)
flashcards
Unit 4 vocabulary
55
Updated 1155d ago
0.0(0)
flashcards
NUR-111: Unit 1
90
Updated 440d ago
0.0(0)
flashcards
LOTF Vocabulary List #2
20
Updated 154d ago
0.0(0)
flashcards
Biosci 221 Exam 3
68
Updated 1064d ago
0.0(0)
flashcards
Wijsbegeerte begrippen deel III
40
Updated 823d ago
0.0(0)
flashcards
biology review: test 1
67
Updated 951d ago
0.0(0)
flashcards
William Billiam exam 4
22
Updated 206d ago
0.0(0)