Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 5Objective 2

5.2 - Design Identification and Authentication Strategy (e.g., People, Devices, and Services) CISSP Practice Questions (Page 3)

Part of the Identity and Access Management (IAM) domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
10concepts
13%of the exam

Questions 11–15

  1. 11application · medium

    A company is implementing SSO for its employees. They want to ensure that when an employee leaves the company, their access to all applications is revoked immediately. Which approach best supports this requirement?

    Select an answer first
  2. 12application · medium

    A university wants to allow students to access the library system, email, and learning management system with a single login. The systems are maintained by different departments and use different authentication mechanisms. The university also wants to ensure that when a student graduates, their access to all systems is revoked quickly. Which approach best meets these requirements?

    Select an answer first
  3. 13foundation · easy

    Which of the following is a common password-less authentication method?

    Select an answer first
  4. 14expert · hard

    A bank is launching a new online banking platform. They need to verify the identity of new customers remotely. The bank wants to comply with KYC regulations and prevent fraud, but they also want to minimize friction for legitimate customers. Which identity proofing approach best balances these requirements?

    Select an answer first
  5. 15expert · hard

    A company is implementing SSO for its employees across multiple SaaS applications. They want to use OpenID Connect (OIDC) for modern applications and SAML for legacy applications. The security team wants to ensure that MFA is enforced for all users. Which approach best achieves this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.