
EC-CouncilCertified Security Specialist
Domain 1Objective 2
Identification, Authentication, and Authorization ECSS Practice Questions (Page 2)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
46questions here
10free pages
9concepts
Questions 6–10
- 6
A multinational company wants to implement SSO across its subsidiaries, each of which uses a different identity provider. The goal is to allow employees to access all internal applications with a single login, while each subsidiary retains control over its own user directory. Which architecture best achieves this?
Select an answer first - 7
A company's security policy requires that remote employees authenticate with both a password and a one-time code from an authenticator app. An employee reports that the authenticator app is not generating codes. Which fallback option would still satisfy the MFA requirement?
Select an answer first - 8
A system assigns each user a unique numeric value that is used to identify the user in system logs and access control records. What is this value called?
Select an answer first - 9
Which authentication mechanism uses a physical device that generates a time-based code that changes periodically?
Select an answer first - 10
Which of the following is a core component of an Identity and Access Management (IAM) system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.