Soru

Zorluk: KolayIdentity and Access Management Operations

A security analyst is establishing the standard administrative workflow for user onboarding and offboarding within an enterprise Identity and Access Management (IAM) system. Place the following identity lifecycle steps in the correct chronological order from first to last.

  1. 1Perform identity verification and background identity proofing
  2. 2Provision account credentials and grant role-based authorization
  3. 3Register and enroll Multi-Factor Authentication (MFA) tokens
  4. 4Conduct periodic access recertification and perform final deprovisioning

Cevap

The proper sequence for identity and access management operations begins with identity verification, followed by account provisioning with role-based access, MFA token enrollment, and finally access recertification and deprovisioning.
The correct operational order follows the standard Identity and Access Management (IAM) lifecycle: first verify the person's identity, then provision the account with appropriate rights, enroll the user in MFA for secure access, and continuously perform access recertification and eventual account deprovisioning.

Adım Adım Çözüm

1
Identify initial identity validation
Identity verification and identity proofing must occur first.
Organizations must confirm the identity of an individual before creating user accounts or granting enterprise resource access.
2
Establish digital credentials
Account provisioning and role assignment occur next.
An active account object in the domain directory is required before secondary security configurations can take place.
3
Apply strong authentication controls
Multi-Factor Authentication (MFA) enrollment follows credential provisioning.
The user binds their hardware token or authenticator app to their newly created user account.
4
Manage ongoing operations and termination
Access recertification and deprovisioning represent the operational audit and end-of-lifecycle phase.
Privilege recertification audits entitlement drift over time, and deprovisioning revokes rights when employment ends.

Anahtar Kavram

Identity Lifecycle Management
Bu soruyu puanla