Identity and Access Management

22 important questions on Identity and Access Management

In Reviewing IAM Introduction:


Match the IAM construct with its definition.

AuthN

  • Deals with identity
  • Deals with access      

AuthN = Authentication = Deals with identity

In reviewing IAM Introduction:


Match the IAM construct with its definition

AuthZ

  • Deals with identity
  • Deals with access      

AuthZ = Authorization = Deals with access

In reviewing IAM Introductions:

You have to assign an OCID for each resource you create on Oracle Cloud.

True or False?

False
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

In review of Compartments:

A resource can be in more than one compartment. 

True or False?

False

In Review of Compartments:

What is it and why do we need it?

Compartments are logical buckets to place resources.

For isolation and control access.  Isolation and control management.

[Compartments is a type of tool for ORACLE to use for authorization and authentication purpose]

In Review of Compartments:

Compartments are global resources. 

*Meaning that if you have the same compartment but you're in a different region, you have the same resources

True or False?

True

For which three of the following are compartments used?

Policy assignment

Network isolation

Quotas and budget

Organization

Policy Assignment / Quotas and Budget / Organization

In Review of Compartments:

What two factors have to be considered for other user access to your compartments?   

*Think Authorization and Authentication!

Groups (Who gets the resources?) and Policies (What are the rules?)

In review of compartments:

What is tenancy another word for?

What can you host inside your root compartment?

Tenancy = account

You can host different networks (that hold resources)

In reviewing AuthN and AuthZ:

What is a principle?

IAM Entities that are allowed to interact with OCI resources

Reviewing AuthN and AuthZ:

What are the three principles mentioned that interact with OCI?

  • IAM Users
    • Humans using your cloud resources
  • *Resources themselves*
    • An example is an instance which becomes a principle - it can make API calls against other OCI services like storage
  • Groups
    • Collection of users with the same type of access requirements to resources

Reviewing AuthN and AuthZ:

What are the three examples of AuthN mentioned in the course?

  • Usernames / Passwords
    • Signing in to websites

  • Authentication tokens
    • Securely transmitting your information between websites

  • API Signing key
    • For API signing calls

Reviewing AuthN and AuthZ:

What is the one example for AuthZ given in the course?

  • IAM Policies
    • Defending user permissions

Reviewing AuthN and AuthZ:

What happens if IAM Policies are attached to a tenancy?

The policies apply to everything in that tenancy

Reviewing AuthN and AuthZ:

What happens if IAM Policies are attached to a compartment?

Policies apply to only the resources

Reviewing Tenancy (Account) Setup:


Which three are recommended best practices?


1 - Enforce Multi-Factor Authentication (MFA).

2 - Use compartments to isolate resources.

3 - Share a single account with all the OCI admins.

4 - Don't use the Tenancy Administrator for day-to-day operations.

1 2 and 4

Reviewing Tenancy (Account) Setup:

IAM resources do not have an aggregate resource type.

FALSE

TRUE

True
[You have to use them individually]

Which Identity and Access Management component helps to organize multiple users into a team?

Compartments

Policies

Groups

Dynamic Groups

Groups
[In OCI IAM, groups are used to group users that serve a common purpose or belong to the same team. This allows policies to be applied at the group level, rather than individually.]

Which is NOT a component of OCI Identity and Access Management?

Federation

Policies

Network Security Group

Principals

Network Security Group

[The Network Security Group is a component of OCI Networking, not IAM. IAM in OCI consists of Principals, Policies, Federation, and a few other components.]

Which statement about OCI Identity and Access Management is true?

It is used to protect information on devices.

It enables you to control access for a group of users.

It enables authentication for devices only

It enables authorization for on-premises users only

It enables you to control access for a group of users.

[OCI Identity and Access Management (IAM) service allows you to control who has access to your cloud resources. It can be used to group users and specify their permissions to provide controlled access to resources.]

Which statement about OCI compartments is NOT true?

Compartments can be nested.

A compartment is a logical collection of related resources.

Compartments help to isolate and control access to resources.

It is a best practice to create all your resources in the root compartment.

It is a best practice to create all your resources in the root compartment.

[It is not a best practice to create all resources in the root compartment. Compartments are used to organize and isolate resources to provide a finer level of access control.]

How is a resource in OCI identified?

With OCID

With Compartment Name

With Username

With Tenancy ID

With OCID
[Each resource in OCI is assigned a unique Oracle Cloud Identifier (OCID), which is used to identify the resource.]

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo