CFS136 · Principles of Information Security

Chapter 7 Review: Identity and Access Management

A hands-on review station for the account lifecycle, account types, multi-factor authentication, access control models, and federation from Chapter 7.

Start Here

Five review stations, each a different way to practice Chapter 7. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Describe the account lifecycle: provisioning, rights assignment, identity proofing, and secure deprovisioning.
  • Tell apart standard, privileged, service, third-party, and emergency accounts and the controls each one needs.
  • Explain multi-factor authentication and weigh the tradeoffs of the three factors: something you know, have, or are.
  • Compare access control models: RBAC, ABAC, MAC, DAC, and just-in-time access by complexity and security.
  • Explain federated identity (SAML, OAuth, OpenID Connect) and single sign-on, plus modern password guidance and passkeys.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/7Model answers correct
0/7Factor answers correct
0/7Account answers correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.