SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CC · Domain 3

Identity And Access Management (IAM) Concepts practice questions

Identity And Access Management (IAM) Concepts is worth 20% of the CC exam — the 3rd-heaviest of the 5 domains. Identity lifecycle management and logical access controls. Official weighting 20%. 6 fully worked examples are further down this page, answers included.

Exam weight
20%
the 3rd-heaviest of the 5 domains
Questions
40
across 2 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Identity And Access Management (IAM) Concepts questions, fully explained

Questions from the CC bank mapped to domain 3, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CC practice page.

Question 1Identity And Access Management (IAM) Concepts

In the Joiner-Mover-Leaver (JML) model, which identity life cycle activity corresponds to the Joiner event?

Choose one.

  • a
    Deprovisioning the user account

    Deprovisioning corresponds to the Leaver event, when a person separates from the organization, not to a new hire joining.

  • b
    Running a periodic access recertification

    Recertification is a review activity performed on existing users throughout their tenure; it is not the event that occurs when someone first joins.

  • c
    Provisioning a new account with the access the role requires Correct

    A Joiner is a new hire; the matching activity is provisioning, which creates the account and grants only the access defined for the person's role.

  • d
    Disabling the account and preserving its audit data

    Disabling an account while preserving audit data is part of handling a Leaver at separation, not a Joiner starting employment.

The concept

The Joiner-Mover-Leaver model maps organizational events to identity life cycle activities: joiners are provisioned, movers have access adjusted and reviewed, and leavers are deprovisioned.

Why that’s the answer

When a person joins the organization, the identity system must create their unique account and grant the access their defined role requires. That granting activity is provisioning, so Joiner maps directly to provisioning.

How to reason it out
  1. Identify the JML event: a Joiner is a person newly entering the organization.
  2. Match the event to the life cycle: entry requires creating an account, which is provisioning.
  3. Apply least privilege at that moment: grant only the access the person's role was defined to need.
  4. Contrast with the other events: Movers trigger access adjustment and review, Leavers trigger deprovisioning.

Exam tip: Joiner means provision, Mover means adjust and review, Leaver means deprovision.

Identity Life Cycle Management: Provisioning, Review, and Deprovisioning — the lesson that teaches this.

Question 2Identity And Access Management (IAM) Concepts

What does provisioning mean in identity life cycle management?

Choose one.

  • a
    Removing a user account when an employee resigns

    Removing access at separation is deprovisioning, the final phase of the life cycle, not provisioning.

  • b
    Creating a user account and granting it the access its role requires Correct

    Provisioning is the act of creating the identity and assigning the entitlements defined for the person's role, and no more than that.

  • c
    Confirming that existing users still need the access they hold

    Confirming that access is still appropriate is the review or recertification phase, which happens after access has already been granted.

  • d
    Backing up user data before an account is deleted

    Preserving data before deletion is a records retention concern handled during deprovisioning; it is not what provisioning means.

The concept

Provisioning is the life cycle phase in which a user account is created and granted the specific access defined for the user's role.

Why that’s the answer

The defining feature of provisioning is granting access: the account is created and receives exactly the entitlements the roles definition phase said the job requires. Options describing removal, review, or data backup describe other phases of the life cycle.

How to reason it out
  1. Start from the roles definition: the access a role needs has already been decided.
  2. Create a unique account for the new user so their actions remain attributable.
  3. Grant only the entitlements defined for the role, applying least privilege from day one.
  4. Hand the account over to the review phase, which will later confirm the access is still needed.

Exam tip: Provisioning grants access; it should grant only what the defined role requires and nothing extra.

Identity Life Cycle Management: Provisioning, Review, and Deprovisioning — the lesson that teaches this.

Question 3Identity And Access Management (IAM) Concepts

Why should every user be issued a unique account rather than sharing a single account with teammates?

Choose one.

  • a
    Unique accounts reduce the total number of passwords the organization must store

    Unique accounts actually increase the number of credentials in the system; password count is not the reason they are required.

  • b
    Unique accounts eliminate the need for periodic access reviews

    Access reviews are still required for unique accounts because privilege creep and role changes affect individual accounts too.

  • c
    Unique accounts make actions attributable to a specific person, preserving accountability Correct

    When each person has their own account, log entries can be tied to an individual; shared accounts make it impossible to prove who performed an action.

  • d
    Unique accounts allow several people to work at the same time

    Concurrency is a technical convenience, not the security rationale; the requirement exists to preserve accountability, not to enable simultaneous logins.

The concept

Accountability requires that every action in a system be traceable to a single individual, which is only possible when each user has a unique account.

Why that’s the answer

Audit logs record which account performed an action. If an account is shared by several people, the log cannot identify which person acted, so accountability is destroyed. Issuing a unique account to every user keeps every logged action attributable to exactly one individual.

How to reason it out
  1. Recognize that audit trails record account identifiers, not the human at the keyboard.
  2. Note that a shared account maps many people to one identifier, so no single person can be held responsible.
  3. Issue a unique account per user so each log entry points to exactly one individual.
  4. Prohibit shared accounts as policy, because they destroy accountability even when convenient.

Exam tip: One person, one account: unique accounts exist to preserve accountability, and shared accounts destroy it.

Identity Life Cycle Management: Provisioning, Review, and Deprovisioning — the lesson that teaches this.

Question 4Identity And Access Management (IAM) Concepts

What is privilege creep?

Choose one.

  • a
    The gradual accumulation of access rights a user no longer needs as they change roles over time Correct

    Privilege creep is exactly this: old entitlements are kept while new ones are added, so access grows beyond what the current job requires.

  • b
    An attacker escalating from a standard account to an administrator account

    That describes privilege escalation, an attack technique, not the slow administrative accumulation of unneeded rights called privilege creep.

  • c
    Granting a new hire more access than their role requires on day one

    Over-provisioning at hire is a least privilege failure at the start, whereas privilege creep is accumulation over time as roles change.

  • d
    An account that remains active after its owner has left the organization

    An active account with no current owner is an orphaned account, a deprovisioning failure, not privilege creep.

The concept

Privilege creep is the gradual, unintended accumulation of access rights as a user moves between roles without their old access being removed.

Why that’s the answer

The defining elements are gradual accumulation and role change: each move adds new entitlements while previous ones are never revoked, so the user ends up with far more access than their current job requires. This is the classic Mover risk in the JML model.

How to reason it out
  1. A user is provisioned with least privilege for their first role.
  2. The user transfers to a new role and receives the new role's access, but the old access is not removed.
  3. Over several moves the account accumulates entitlements no single role would justify.
  4. Periodic access reviews detect and strip the excess, restoring least privilege.

Exam tip: Privilege creep is the Mover risk: access accumulates across role changes until a review strips what is no longer needed.

Identity Life Cycle Management: Provisioning, Review, and Deprovisioning — the lesson that teaches this.

Question 5Identity And Access Management (IAM) Concepts

What is an orphaned account?

Choose one.

  • a
    An account that has been disabled pending an investigation

    A disabled account cannot be logged into, so it is not the live, unowned target that defines an orphaned account.

  • b
    An account whose password has expired and must be reset

    An expired password is a routine credential state; the account still has an active owner, so it is not orphaned.

  • c
    A service account that is shared by two applications

    A shared service account raises accountability concerns, but it has active owners and is not the result of a missed deprovisioning.

  • d
    An account that remains active after the person it belonged to has left the organization Correct

    This is the definition: the owner is gone but the account still works, leaving live access that no one is watching.

The concept

An orphaned account is an active account whose owner has separated from the organization, created when deprovisioning fails to happen.

Why that’s the answer

The two defining traits are that the account still works and that no current employee owns it. Because nobody is using or monitoring it legitimately, an attacker who compromises it can operate with little chance of the real owner noticing, which makes orphaned accounts prime attacker targets.

How to reason it out
  1. A person leaves the organization, which should trigger the Leaver deprovisioning step.
  2. Deprovisioning is missed or delayed, so the account remains active with all its access.
  3. The account now has no legitimate user to notice suspicious activity on it.
  4. Attackers seek out such accounts because compromise is unlikely to be reported; prompt deprovisioning and automated IAM workflows prevent them.

Exam tip: An orphaned account is live access with no living owner, and it is one of the most attractive targets an attacker can find.

Identity Life Cycle Management: Provisioning, Review, and Deprovisioning — the lesson that teaches this.

Question 6Identity And Access Management (IAM) Concepts

Which phase of the identity life cycle removes a user's access when they separate from the organization?

Choose one.

  • a
    Roles definition

    Roles definition happens before any access is granted; it decides what a role needs, it does not remove anything.

  • b
    Deprovisioning Correct

    Deprovisioning is the final life cycle phase, in which the departing user's access is removed promptly, typically by disabling the account first.

  • c
    Provisioning

    Provisioning grants access at the start of the relationship; it is the opposite of removing access at separation.

  • d
    Review

    Review confirms whether existing access is still appropriate during employment; it can trigger removals but is not the separation phase itself.

The concept

Deprovisioning is the life cycle phase that removes access when a user leaves, closing out the Leaver event in the JML model.

Why that’s the answer

Separation means the person no longer has any business need for access, so every entitlement must be removed promptly. The phase dedicated to that removal is deprovisioning; the other phases define, grant, or check access rather than ending it.

How to reason it out
  1. The separation event, voluntary or involuntary, triggers the Leaver workflow.
  2. The account is disabled promptly so it can no longer be used to log in.
  3. Audit data and account records are preserved according to the retention policy.
  4. The account is deleted later, once retention requirements allow, completing deprovisioning.

Exam tip: Deprovisioning ends the life cycle: when a person leaves, their access must be removed promptly.

Identity Life Cycle Management: Provisioning, Review, and Deprovisioning — the lesson that teaches this.

What CC domain 3 tests, topic by topic

The official exam guide breaks Identity And Access Management (IAM) Concepts into 2 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CC practice questions per topic in Identity And Access Management (IAM) Concepts
TopicWhat it coversQuestions
Understand identity life cycle managementOfficial CC sub-domain (IAM Concepts, Sept-2026 outline). Roles definition, provisioning, review, and deprovisioning; and identity frameworks and tools.20
Understand logical access controlsOfficial CC sub-domain. The Principle of Least Privilege (PoLP), Separation of Duties (SoD), and access control models (e.g., DAC, MAC, RBAC).20
Total40

Revise Identity And Access Management (IAM) Concepts before you drill it

Other CC domains

Identity And Access Management (IAM) Concepts: your questions

Identity And Access Management (IAM) Concepts is domain 3 of the CC exam guide and carries 20% of the scored content — the 3rd-heaviest of the 5 domains. On a 100-question paper that works out to roughly 20 questions, though ISC2 does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CC exam guide.