BTCE | 5th Sem
SPC SubjectUnit 2

SPC Unit 2: Questions & Answers

Unit 2: Access Control and Identity Management -> Generated and Prepared By Thiruselvan (ThiruXD)

Multiple Choice Questions (MCQs) – 50

1. The primary requirement of access control in cloud infrastructure is to ensure:

a) Unlimited access for all users

b) Only authorized users and services can access specific resources

c) Access is granted based only on IP address

d) No authentication is required

Answer: b

2. User identification in cloud environments typically involves:

a) Only physical appearance

b) Unique identifiers such as usernames, email addresses, or digital certificates

c) Only MAC addresses

d) Only biometric data without verification

Answer: b

3. Authentication is the process of:

a) Granting permissions to resources

b) Verifying the identity of a user or system

c) Logging all activities

d) Encrypting data

Answer: b

4. Authorization determines:

a) Who the user is

b) What actions an authenticated user is allowed to perform

c) How data is encrypted

d) Network routing

Answer: b

5. Role-Based Access Control (RBAC) assigns permissions based on:

a) Individual user attributes only

b) Roles that users are assigned to

c) Time of day only

d) Geographic location only

Answer: b

6. Multi-Factor Authentication (MFA) requires:

a) Only a password

b) Two or more independent authentication factors

c) Only a security token

d) Only biometric data

Answer: b

7. Single Sign-On (SSO) allows a user to:

a) Log in once and access multiple applications without re-authenticating

b) Use different passwords for every application

c) Bypass all authentication

d) Share credentials freely

Answer: a

8. Identity Federation enables:

a) Users from one organization to access resources in another using their home identity

b) Creation of new identities for every service

c) Disabling of all external access

d) Only local authentication

Answer: a

9. An Identity Provider (IdP) is responsible for:

a) Storing application data

b) Authenticating users and asserting their identity to service providers

c) Managing network traffic

d) Encrypting storage only

Answer: b

10. A Service Provider (or Service Consumer) in federation relies on the IdP for:

a) Authentication decisions

b) Data storage

c) Network configuration

d) Hardware provisioning

Answer: a

11. Storage access control options in cloud typically include:

a) Bucket policies, IAM policies, ACLs, and signed URLs

b) Only physical locks

c) Only network firewalls

d) Only antivirus software

Answer: a

12. Network access control options commonly include:

a) Security groups, Network ACLs, private endpoints, and zero-trust policies

b) Only physical switches

c) Only DNS settings

d) Only email filters

Answer: a

13. Operating system hardening aims to:

a) Increase the number of installed packages

b) Reduce the attack surface by removing unnecessary services and applying security configurations

c) Disable all logging

d) Grant maximum privileges

Answer: b

14. Verified boot ensures that:

a) The system boots as fast as possible

b) Only trusted and unmodified software components are loaded during boot

c) All network interfaces are disabled

d) Users can log in without passwords

Answer: b

15. Measured boot records:

a) The time taken to boot

b) Cryptographic measurements (hashes) of boot components for later attestation

c) Only user login times

d) Network bandwidth usage

Answer: b

16. An Intrusion Detection System (IDS) primarily:

a) Blocks malicious traffic automatically

b) Monitors and detects suspicious activity and generates alerts

c) Encrypts all network traffic

d) Manages user identities

Answer: b

17. An Intrusion Prevention System (IPS) differs from IDS because it:

a) Only logs events

b) Can actively block or prevent detected threats in real time

c) Requires no signatures

d) Works only on endpoints

Answer: b

18. A common authentication mechanism in cloud is:

a) Username/password combined with MFA

b) Only MAC address filtering

c) Only physical keys

d) Open access

Answer: a

19. In RBAC, the principle of least privilege is achieved by:

a) Assigning users to roles with only necessary permissions

b) Giving every user administrator rights

c) Never reviewing roles

d) Using only attribute-based controls

Answer: a

20. Which factor is commonly used in MFA?

a) Something you know (password), something you have (token), something you are (biometric)

b) Only something you know

c) Only IP address

d) Only time of day

Answer: a

21. SSO protocols commonly used in cloud include:

a) SAML, OAuth 2.0, and OpenID Connect

b) Only FTP

c) Only Telnet

d) Only SNMP

Answer: a

22. Identity federation is often implemented using:

a) SAML or OpenID Connect assertions

b) Shared passwords across organizations

c) Physical ID cards only

d) Manual account creation for every user

Answer: a

23. In a federated identity model, the relying party is also known as the:

a) Identity Provider

b) Service Provider / Service Consumer

c) Certificate Authority

d) Network firewall

Answer: b

24. Storage access can be controlled using temporary credentials via:

a) Pre-signed URLs or temporary security tokens

b) Permanent root passwords

c) Shared public keys only

d) No access control

Answer: a

25. Network Access Control (NAC) in cloud environments often enforces:

a) Policies based on identity, device posture, and context before granting network access

b) Only MAC address allow-lists

c) Unlimited access once inside the VPC

d) Only outbound filtering

Answer: a

26. OS minimization involves:

a) Installing only the packages and services required for the workload

b) Installing every available package

c) Disabling security updates

d) Running all services as root

Answer: a

27. Verified boot relies on:

a) A chain of trust starting from a hardware root of trust

b) User passwords only

c) Network authentication only

d) Application-level checks only

Answer: a

28. Measured boot enables:

a) Remote attestation of the system’s boot integrity

b) Faster boot times

c) Automatic software updates

d) User session management

Answer: a

29. Signature-based IDS detects threats by:

a) Matching known attack patterns or signatures

b) Only analyzing user behavior

c) Encrypting traffic

d) Managing identities

Answer: a

30. Anomaly-based IDS detects threats by:

a) Identifying deviations from normal behavior baselines

b) Only using predefined signatures

c) Blocking all traffic

d) Managing encryption keys

Answer: a

31. A key access control requirement for cloud infrastructure is:

a) Support for fine-grained, dynamic, and auditable access decisions

b) Permanent open access

c) No logging of access

d) Only physical access control

Answer: a

32. Biometric identification is an example of:

a) Something you are

b) Something you know

c) Something you have

d) Something you do only

Answer: a

33. Authorization can be implemented using:

a) Access Control Lists (ACLs), RBAC, or Attribute-Based Access Control (ABAC)

b) Only passwords

c) Only encryption

d) Only network segmentation

Answer: a

34. In RBAC, a role is a collection of:

a) Permissions

b) User passwords

c) Network routes

d) Encryption keys

Answer: a

35. Time-based one-time passwords (TOTP) are commonly used in:

a) Multi-Factor Authentication

b) Single Sign-On only

c) Network routing

d) Storage encryption

Answer: a

36. Federated identity reduces the need for:

a) Creating and managing separate accounts in every service provider

b) Strong authentication

c) Encryption

d) Logging

Answer: a

37. Identity Providers can be:

a) Corporate directories (Active Directory, Azure AD, Okta, etc.) or social IdPs

b) Only local password files

c) Only hardware tokens

d) Only network switches

Answer: a

38. Object-level access control in cloud storage allows:

a) Permissions to be set on individual objects in addition to the container/bucket

b) Only bucket-level permissions

c) No permissions at all

d) Only public access

Answer: a

39. Security groups in cloud platforms act as:

a) Virtual firewalls controlling inbound and outbound traffic at the instance level

b) Physical firewalls only

c) Identity providers

d) Encryption services

Answer: a

40. Hardening an operating system typically includes:

a) Disabling unused ports and services, applying patches, and configuring secure settings

b) Installing additional unnecessary software

c) Disabling firewalls

d) Sharing root credentials

Answer: a

41. The root of trust in verified boot is usually:

a) Hardware-based (TPM or secure boot firmware)

b) A user password

c) An application certificate only

d) Network configuration

Answer: a

42. IDS sensors can be deployed as:

a) Network-based or host-based

b) Only cloud storage

c) Only identity providers

d) Only encryption modules

Answer: a

43. IPS systems can operate in:

a) Inline mode to actively block traffic or passive mode for detection

b) Only offline analysis

c) Only identity management

d) Only key management

Answer: a

44. A major benefit of SSO is:

a) Improved user experience and reduced password fatigue

b) Weaker security

c) Elimination of all authentication

d) Increased number of passwords

Answer: a

45. Attribute-Based Access Control (ABAC) makes decisions based on:

a) Attributes of the user, resource, action, and environment

b) Only assigned roles

c) Only IP addresses

d) Only time of day

Answer: a

46. Just-In-Time (JIT) access is a modern access control technique that:

a) Grants elevated privileges only when needed and for a limited time

b) Grants permanent administrator rights

c) Disables all access

d) Requires no authentication

Answer: a

47. Network ACLs typically operate at the:

a) Subnet level

b) Individual process level only

c) Application code level only

d) User interface level

Answer: a

48. OS minimization reduces risk by:

a) Decreasing the number of potential vulnerabilities and attack surface

b) Increasing the number of running services

c) Disabling security monitoring

d) Granting more privileges

Answer: a

49. Remote attestation (enabled by measured boot) allows a remote party to:

a) Verify that a system has booted into a trusted state

b) Change the boot configuration

c) Access user data directly

d) Manage network traffic

Answer: a

50. Combining IDS and IPS with identity and access controls provides:

a) Defense-in-depth by detecting, preventing, and controlling access

b) Only detection without prevention

c) Only identity management

d) Only network routing

Answer: a


Theory Questions – 20

1. Explain the key access control requirements for cloud infrastructure.

Answer: Access control in cloud must be fine-grained, dynamic, scalable, auditable, and enforceable across compute, storage, and network resources. It should support multi-tenancy, least privilege, separation of duties, temporary credentials, and integration with identity systems while remaining resilient to misconfiguration.

2. Describe common user identification techniques used in cloud environments.

Answer: Techniques include unique usernames/email addresses, digital certificates, hardware or software tokens, biometric identifiers, device identifiers, and federated identities. Identification establishes a unique digital identity that can later be authenticated.

3. Differentiate between authentication and authorization with examples relevant to cloud.

Answer: Authentication verifies identity (e.g., username + password + MFA, or certificate-based login). Authorization determines permitted actions after authentication (e.g., an authenticated user is allowed to read a specific storage bucket but not delete it). Authentication answers “Who are you?”; authorization answers “What are you allowed to do?”

4. Explain Role-Based Access Control (RBAC) and its advantages in cloud environments.

Answer: RBAC assigns permissions to roles rather than directly to users. Users are then assigned to roles. Advantages include simplified administration, consistent enforcement of least privilege, easier auditing, and scalability in large cloud environments with many users and resources.

5. What is Multi-Factor Authentication (MFA) and why is it critical in cloud security?

Answer: MFA requires two or more independent factors (knowledge, possession, inherence) to verify identity. It is critical because compromised passwords alone are insufficient; MFA significantly reduces the risk of account takeover, especially for privileged cloud accounts.

6. Describe Single Sign-On (SSO) and the protocols commonly used to implement it.

Answer: SSO allows a user to authenticate once and gain access to multiple applications without re-entering credentials. Common protocols include SAML 2.0, OAuth 2.0, and OpenID Connect. SSO improves usability and can centralize authentication policy enforcement.

7. Explain Identity Federation and its benefits.

Answer: Identity federation allows users from one security domain (Identity Provider) to access resources in another domain (Service Provider) without creating separate accounts. Benefits include reduced administrative overhead, improved user experience, centralized control of authentication, and support for cross-organization collaboration.

8. Differentiate between an Identity Provider (IdP) and a Service Provider / Service Consumer.

Answer: The Identity Provider authenticates users and issues security assertions (tokens or SAML assertions). The Service Provider (or Service Consumer) relies on those assertions to grant access to its resources without performing authentication itself.

9. Describe the main storage access control options available in cloud platforms.

Answer: Options include IAM policies (identity-based), resource-based policies (bucket/object policies), Access Control Lists (ACLs), pre-signed URLs or temporary tokens, and condition keys (e.g., source IP, MFA, encryption status). These can be combined for fine-grained control.

10. Explain network access control options commonly used in cloud environments.

Answer: Common options are security groups (stateful, instance-level), Network ACLs (stateless, subnet-level), private endpoints / PrivateLink, VPC peering or transit gateways with controls, zero-trust network access, and network policies in container platforms.

11. What is operating system hardening and minimization, and why are they important?

Answer: Hardening involves applying security configurations, disabling unnecessary services, removing unused software, applying patches, and enforcing secure settings. Minimization reduces the installed footprint to only required components. Both reduce the attack surface and potential vulnerabilities.

12. Explain Verified Boot and Measured Boot.

Answer: Verified Boot (Secure Boot) ensures that only cryptographically signed and trusted components are loaded during the boot process, preventing unauthorized code from running. Measured Boot records cryptographic hashes of boot components (often in a TPM) so that the integrity of the boot process can later be attested remotely.

13. Describe the working of an Intrusion Detection System (IDS).

Answer: An IDS monitors network traffic or host activity for suspicious patterns. It can be signature-based (matching known attack signatures) or anomaly-based (detecting deviations from normal baselines). When a potential intrusion is detected, it generates alerts for administrators.

14. How does an Intrusion Prevention System (IPS) differ from an IDS?

Answer: An IDS is primarily passive—it detects and alerts. An IPS is active—it can block, drop, or reset malicious connections in real time, often by sitting inline in the network path. Many modern systems combine both detection and prevention capabilities.

15. Discuss the importance of least privilege in access control design for cloud.

Answer: Least privilege ensures that users, services, and applications receive only the minimum permissions necessary to perform their functions. This limits the potential damage from compromised credentials, insider threats, or software vulnerabilities.

16. Explain how Just-In-Time (JIT) and Just-Enough-Access (JEA) improve cloud access control.

Answer: JIT grants elevated privileges only when needed and for a limited duration. JEA further restricts the specific commands or actions that can be performed even when elevated access is granted. Together they reduce standing privileges and the attack window.

17. What role does Attribute-Based Access Control (ABAC) play in modern cloud environments?

Answer: ABAC makes access decisions based on attributes of the subject, resource, action, and environment (e.g., user department, resource sensitivity, time, location, device posture). It provides more dynamic and fine-grained control than pure RBAC, especially in complex multi-tenant or zero-trust architectures.

18. Describe how temporary credentials and pre-signed URLs enhance storage security.

Answer: Temporary credentials (from STS or equivalent) expire after a short period, limiting the window of exposure if compromised. Pre-signed URLs grant time-limited access to specific objects without requiring permanent credentials, enabling secure sharing or delegated access.

19. Explain the relationship between identity management and network access control in a zero-trust model.

Answer: In zero-trust, network access is not granted solely based on network location. Identity (strong authentication and authorization) combined with device posture and continuous verification determines whether a connection is allowed. Network controls enforce the identity-driven decisions.

20. Why should IDS/IPS be integrated with identity and access management systems?

Answer: Integration allows correlation of network or host alerts with identity context (who performed the action, from where, with what privileges). This improves detection accuracy, enables automated response (e.g., revoking sessions), and supports forensic investigation and compliance.


Analytical Questions – 10

1. A cloud administrator discovers that a service account with overly broad permissions was compromised. Analyze the impact and recommend a complete set of preventive and detective controls using concepts from access control and identity management.

Answer: Impact includes potential data exfiltration, resource abuse, and lateral movement. Preventive controls: enforce least privilege and RBAC/ABAC, use short-lived temporary credentials, require MFA for human access, implement JIT access, and apply resource-based policies. Detective controls: enable detailed logging (CloudTrail/equivalent), monitor for anomalous API calls, integrate with IDS/IPS, and set alerts on privilege escalations or unusual access patterns. Regular access reviews and automated policy enforcement are essential.

2. An organization wants to allow employees to access multiple SaaS applications using their corporate credentials without creating separate accounts. Design a suitable identity solution and analyze its security benefits and potential risks.

Answer: Implement Identity Federation with an enterprise IdP (e.g., Azure AD, Okta) using SAML or OpenID Connect, combined with SSO. Benefits: centralized authentication, consistent MFA enforcement, reduced password fatigue, easier offboarding, and better auditability. Risks: single point of failure at the IdP, potential token replay if not properly protected, and dependency on the IdP’s availability and security. Mitigate with strong MFA, token encryption/signing, short token lifetimes, and monitoring of federation events.

3. Compare RBAC and ABAC for a multi-tenant cloud application that needs to enforce complex policies based on user department, resource sensitivity, time of day, and location. Which would you recommend and why?

Answer: RBAC is simpler to manage for stable role-based needs but becomes cumbersome when policies depend on multiple dynamic attributes. ABAC can express rich policies using attributes of subject, resource, action, and environment. For complex, context-aware requirements, ABAC (or a hybrid RBAC + ABAC approach) is recommended because it provides the necessary flexibility and granularity while still supporting role abstractions where useful.

4. A company is deploying critical workloads on virtual machines in the cloud. Analyze how OS hardening, minimization, verified boot, and measured boot together improve the security posture of these VMs.

Answer: Minimization and hardening reduce the attack surface by removing unnecessary software and applying secure configurations. Verified boot ensures that only trusted, signed components load at startup, preventing bootkits and unauthorized modifications. Measured boot records the boot measurements, enabling remote attestation so that the cloud platform or security tools can verify the VM has booted into a known-good state before granting it access to sensitive resources. Together they establish a stronger chain of trust from hardware to the running workload.

5. Design a network and storage access control strategy for a sensitive application that must allow temporary access to external partners for specific objects only. Include identity considerations.

Answer: Use federated identity or temporary guest accounts with strong MFA for partners. Grant time-limited, least-privilege IAM roles or generate pre-signed URLs / temporary security tokens scoped to specific storage objects. Place resources in private subnets with security groups and Network ACLs that allow access only from approved sources or via private endpoints. Enable detailed logging and automatic expiration of access. Monitor with IDS/IPS for anomalous access patterns.

6. An organization currently uses only passwords for authentication to cloud consoles and APIs. Analyze the risks and propose a phased plan to implement strong authentication and access controls.

Answer: Risks include credential stuffing, phishing, and account takeover leading to full environment compromise. Phased plan: (1) Enforce strong password policies and enable MFA for all users, starting with privileged accounts; (2) Implement SSO with a central IdP; (3) Move to passwordless or phishing-resistant MFA (FIDO2/WebAuthn) where possible; (4) Introduce RBAC with least privilege and JIT access; (5) Enable comprehensive logging, monitoring, and regular access reviews; (6) Integrate with IDS/IPS for detection of anomalous authenticated activity.

7. Evaluate the effectiveness of security groups versus Network ACLs for controlling east-west traffic in a multi-tier cloud application. How should they be used together with identity controls?

Answer: Security groups are stateful and operate at the instance/ENI level, making them suitable for fine-grained, application-aware rules. Network ACLs are stateless and operate at the subnet level, providing an additional layer of defense. Best practice is to use both (defense in depth). Identity controls (IAM roles, temporary credentials) should determine who can initiate connections, while security groups and NACLs enforce where and what traffic is allowed, implementing a zero-trust approach.

8. A cloud workload is generating repeated alerts from a network-based IDS. Analyze how integrating identity context and access control logs can improve investigation and response.

Answer: Pure network alerts lack context about the identity behind the traffic. Correlating IDS alerts with IAM logs, authentication events, and authorization decisions reveals whether the activity originated from a legitimate user/service, a compromised credential, or an unauthorized principal. This enables faster triage, automated response (e.g., session revocation, role de-provisioning), and more accurate determination of whether the activity is malicious or benign.

9. Design an access control architecture for a containerized application platform (e.g., Kubernetes on cloud) that enforces least privilege at both the infrastructure and application layers.

Answer: At infrastructure level: use cloud IAM roles for nodes and control plane with minimal permissions, security groups, and private networking. At platform level: enable RBAC in Kubernetes, use service accounts with least privilege, network policies for micro-segmentation, and Pod Security Standards / admission controllers. Integrate with an external IdP for user authentication (OIDC), enforce MFA, and apply JIT access for administrative operations. Continuously monitor with IDS/IPS and audit logs.

10. An auditor asks how the organization ensures that only trusted operating systems are running in the cloud and that any compromise of the boot process would be detected. Provide a detailed technical response covering the relevant technologies.

Answer: The organization uses hardened and minimized golden images. Verified/Secure Boot ensures that the firmware and bootloader only load cryptographically signed components, establishing a chain of trust from the hardware root of trust (TPM or equivalent). Measured Boot records hashes of each boot stage in the TPM’s Platform Configuration Registers (PCRs). Remote attestation allows the cloud platform or a security service to verify these measurements against known-good values before the instance is allowed to join the environment or access secrets. Any deviation (indicating tampering) causes attestation to fail, preventing the compromised system from operating with trusted credentials. Continuous monitoring and IDS further detect post-boot anomalies.


On this page