All questions

Perform User Account Management Phase 1 Practice Test

Browse all practice questions for the Perform User Account Management Phase 1 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Master User Account Wizardry 2026: Unlock Phase 1 Success with Our Dynamic Practice Test! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which statement best describes SCIM in provisioning?
  • Which session management control most directly helps reduce risk from long-lived sessions?
  • PKI (Public Key Infrastructure) is...
  • When you suspect a compromised user account, which steps should you take?
  • What are common uses for symmetric encryption?
  • What best describes a least-privilege access certification?
  • Which function is included in Outlook for planning events?
  • What is identity governance designed to do?
  • What is a key component of disaster recovery readiness for identity management?
  • What is the first step in the user onboarding workflow for account creation?
  • What role does a central identity provider play in RBAC for multiple apps?
  • Which statement best describes a domain in Active Directory?
  • Why is device-based conditional access important?
  • In a directory service, which attribute set is typically stored for each user, including user ID, username, email, department, and MFA status?
  • What is the correct structure order for Active Directory schema?
  • How do ABAC and RBAC differ, and when would you choose ABAC?
  • Which best describes Cyber Awareness Training focus?
  • PKI management involves which activity?
  • Which of the following is NOT a listed type of user account?
  • In common OAuth/OpenID Connect flows, how are access tokens rotated and revoked?
  • In Active Directory, a domain is best described as:
  • How would you implement password policy requirements in a directory?
  • Which statement describes the relationship between EAC and Microsoft 365?
  • Which statement describes a just-in-time access practice?
  • In an SSO environment, provisioning of user accounts to downstream applications is typically:
  • Which statement describes deprovisioning in an IAM lifecycle?
  • Which policy governs the Army IT UAA?
  • What is the purpose of organizational units (OUs) in Active Directory?
  • What does it mean to Decommission a User Account?
  • Which items are typically monitored as part of an auditing and logging program in IAM?
  • Which metric is commonly used to measure how quickly new user accounts are provisioned?
  • Which item is least likely to appear in IAM compliance reports?
  • Describe a typical user lifecycle flow from onboarding to offboarding.
  • In an SSO-enabled environment, what is the role of an identity provider?
  • Which option demonstrates best practice when testing provisioning changes before production?
  • What is the purpose of Cyber Awareness Training?
  • What are impossible travel risk signals?
  • What does Cross-Premise Navigation in EAC allow?
  • What is SCIM and how does it relate to user provisioning?
  • Which elements enable context-aware authentication?
  • Why is a robust audit trail important in IAM governance?
  • How does Microsoft Outlook primarily operate?
  • How should you differentiate a cancelled user from a terminated employee in access control?
  • Which password policy element is most associated with reducing helpdesk resets?
  • SSL and TLS stand for?
  • Which infrastructure option does Outlook depend on to deliver its core capabilities?
  • What is a key reason to maintain audit trails for password resets?
  • What is the difference between SCIM provisioning and provisioning via custom scripts?
  • In offboarding, which action is essential to immediately remove access?
  • Who has access to ATCTS?
  • What are best practices for IP allowlisting?
  • What is the role of identity verification in onboarding?
  • In RBAC, what is a common pitfall that arises when roles accumulate permissions over time?
  • What is privileged access management (PAM) and how does just-in-time (JIT) access reduce risk?
  • Which metric indicates how many privileged access reviews have been completed?
  • What is SCIM and how does it support automated user provisioning?
  • How do device trust and location influence login access controls?
  • Which approach helps prevent stale credentials when users leave or change roles?
  • What is a user account?
  • What is SCIM synchronization and which attributes are commonly synced?
  • Which practice best supports controlled elevation of privileges with proper governance?
  • Which statement about Microsoft Exchange Server is correct?
  • Which action would typically apply a GPO to all objects within a domain?
  • What constitutes a solid audit trail for IAM changes?
  • How should data retention and access rights be handled to align with policy?
  • How many types of user accounts are defined in the material?
  • What is the purpose of the hierarchical structure in Active Directory?
  • Under what circumstances is ABAC preferred over RBAC for enforcing least privilege?
  • Which is a type of security group?
  • Which is NOT a core capability of Outlook as described?
  • What is the purpose of GPOs?
  • Which components should be included in a strong password policy, and how do you implement lockout safeguards?
  • Which statement best describes policy coverage for identity terminations and cancellations?
  • In identity and access management, what defines an orphaned account?
  • Just-in-time access in privileged access management refers to:
  • How should organizations handle exceptions to access policies?
  • What is the purpose of a service catalog in account management?
  • In provisioning tests, which environment should be used to simulate real-world usage safely?
  • Which statement describes benefits of Active Directory?
  • What is least privilege and why is it critical in account management?
  • How do you establish trust between identity providers in a federated setup?
  • Which practice best describes management of service accounts?
  • Which practice supports reconciliation of user state across systems by ensuring consistency of identity attributes?
  • Which approach correctly handles privileged escalation requests?
  • Which security measure best applies to self-service password reset?
  • In access control, how do rights differ from permissions?
  • Which approach best enables time-bound or recurring temporary access?
  • Active Directory is best described as:
  • In SSL/TLS, which best describes the encryption workflow?
  • How many parts are there in an Army IT User Access Agreement?
  • How should data associated with deprovisioned accounts be handled for compliance?
  • Explain the concept of "separation of duties" in account management.
  • What is the main difference between symmetric and asymmetric encryption?
  • In identity management, what is the purpose of an account owner or sponsor?
  • How do you deprovision access for a terminated employee?
  • What are the key attributes stored for a user in a directory?
  • What is a conditional access policy?
  • Which description best characterizes a guest account?
  • Which statement correctly describes the flow of SAML-based single sign-on?
  • How do you perform account provisioning via automation?
  • What does placing a GPO at the root of the domain affect?
  • Which of the following is a component of Army IT UAA's Part II?
  • Integrity in CIA refers to what?
  • Which authentication protocols are commonly used in enterprise IAM?
  • What is Group Policy?
  • What is Exchange Admin Center (EAC)?
  • What is a tree in Active Directory?
  • A forest in Active Directory is:
  • Which statement best describes the domain's role in Active Directory?
  • What is the name of a DD Form 2875?
  • How should exceptions that use temporary tokens be managed?
  • Describe the characteristics of service accounts and best practices for their management.
  • Cross-Premise Navigation in EAC is used to switch between which environments?
  • What does modifying an account consist of?
  • Cross-Premise Navigation allows switching between which environments?
  • What is access packaging and how can it simplify onboarding?
  • How would you implement passwordless authentication in an enterprise environment?
  • Which scenario best illustrates least-privilege access?
  • What control is typically required for a break-glass account?
  • What should training and awareness for account management cover?
  • Which statement reflects GDPR/CCPA considerations for retention and processing of user data?
  • Which statement about multifactor authentication (MFA) is true?
  • What is SAML, and how does it enable SSO in an enterprise environment?
  • Which statement best defines RBAC in the context of user account management?
  • What is a GPO?
  • What does the CIA acronym stand for?
  • What is a typical recommended lockout policy for failed login attempts?
  • Which feature is listed as part of Outlook's offering?
  • How can you implement time-bound or recurring temporary access?
  • Which SCIM consideration is important when schemas change?
  • What is the role of license management in user accounts?
  • What considerations are important when migrating user accounts between systems?
  • What training is submitted with the DD Form 2875?
  • What can happen if a user uses Army networks unauthorized?
  • Which statement best reflects the principle of least privilege?
  • Revocability as it pertains to Army IT UAA?
  • How would you detect and respond to a compromised user account?
  • What is the role of role mapping in access management?
  • What are common uses for asymmetric encryption?
  • Which GDPR/CCPA considerations are important for handling user account data and retention?
  • What does ATCTS stand for?
  • Which item would best appear in IAM compliance reporting?
  • Which information Cyber Awareness Training reinforces best practices to protect?
  • What is the practical difference between OAuth 2.0 and OpenID Connect?
  • What is API-based account provisioning?
  • What is the purpose of access tokens and refresh tokens?
  • Which statement accurately describes how Outlook relies on server infrastructure?
  • How do you handle guest access and external collaborators?
  • What describes a just-in-time access model?
  • SSL/TLS use which type of encryption?
  • Why is maintaining an audit trail important for privileged escalation?
  • A domain controller is:
  • Confidentiality in CIA is defined as?
  • What is the purpose of the Army IT User Access Agreement?
  • ATCTS IA data sources include which of the following?
  • What is a key benefit of regular access reviews in RBAC?
  • The Exchange Admin Center primarily serves as what?
  • Which control is commonly applied to guest accounts to reduce risk?
  • What does Single Sign-On (SSO) achieve in user account management?
  • Why is auditing and logging important in user account management?
  • When would you typically use groups versus roles for access management, and what are the benefits?
  • What are the strengths and weaknesses of self-service password reset, and how should it be secured?
  • What does the principle of least privilege require in an IAM program and how is it enforced?
  • How would you enforce device compliance before granting access?
  • What is a service account and what special controls apply?
  • In federated identity management, which practice helps maintain trust between identity providers?
  • The three parts of an Army IT UAA?
  • What is considered a secure practice for password resets?
  • PKI stands for?
  • What is the purpose of access reviews in a user account management program?
  • Which practice supports reconciliation of user state across systems?
  • Which statement best describes authentication and authorization?
  • Which describes the primary purpose of ATCTS?
  • Which of the following best summarizes the purpose of Outlook's offering?
  • Which scenario best describes a soft delete behavior?
  • Regarding audit logs, which statement best describes how they should be protected and accessible?
  • Which offboarding action is a primary step to prevent continued access when an employee leaves?
  • Which features are included in Microsoft Outlook's offerings?
  • What are the three types of Security Groups?
  • Why is consent management relevant in user account management?
  • Which statement about dynamic distribution groups is true?
  • Which of the following is NOT listed as a reason to decommission a user account?
  • A benefit of ATCTS is
  • What should consent management support regarding withdrawal and privacy laws?
  • Which of the following is a way to verify a user's membership in security groups?
  • Which MFA configurations are considered secure, and what fallback methods should be prepared?
  • What are the two types of cryptographic algorithms?
  • How does onboarding differ for contractors versus permanent employees?
  • Which statement about asymmetric encryption is true?
  • Which statement best describes typical components of IAM compliance reporting?
  • ATCTS imports training and certification completion data from which DoD systems?
  • What describes a shadow IT risk in account management?
  • What distinguishes a dynamic distribution group from a regular distribution group?
  • What is HR-driven lifecycle management and why is it important for IAM?
  • Which statement best describes rights vs permissions?
  • Which statement best describes delegated administration in IAM?
  • What is a break-glass account and when is it used?
  • Which authentication practice is preferred for onboarding rather than security questions?
  • Which action best ensures disaster recovery readiness for identity services?
  • How do you audit for least privilege over time?
  • Which statement best describes how to handle service accounts in practice?
  • Which statement best defines a domain in Active Directory?
  • How do SSO and MFA complement each other in a typical user login flow?
  • ATCTS stores which documents for users?
  • What are best practices for storing and rotating credentials?
  • Which elements are involved in validating access requests?
  • What is the difference between LDAP and SAML in account management?
  • How do you handle account lockout policies and lockout thresholds?
  • What does Cyber Awareness Training provide?
  • Where can you modify a user's security groups?
  • Which activity is essential to validate permissions when testing provisioning changes?
  • Which events should be audited in a user account system, and how should the logs be protected?
  • In user account management, which statement correctly describes provisioning and deprovisioning?
  • How do roles and permission sets differ in their use for access management?
  • Which of the following is NOT a common use for symmetric encryption?
  • Which credential storage and rotation practice aligns with security best practices?
  • Which approach best implements separation of duties in an IAM program?
  • Which step is essential when testing provisioning changes before production?
  • Which benefit does access packaging provide during onboarding?
  • Which practice is consistent with minimizing risk in identity management?
  • Why are security questions not recommended as a primary authentication method?
  • What is the difference between a user, a service account, and a guest account?
  • Which statement best describes provisioning in an IAM lifecycle?
  • The web-based console for Exchange Server is designed to align with which suite?
  • What is Microsoft Exchange Server?
  • What should you check before modifying a user account?
  • What is an access review and when should it be conducted?
  • What is the purpose of a rollback plan when testing provisioning changes before production?
  • Active Directory saves information about network objects and makes it easier to use. This statement describes:
  • Which of the following can be contained within an Organizational Unit?
  • Which statement correctly distinguishes hard delete from soft delete in account management?
  • Which office is the proponent for the Army IT UAA?
  • Availability in CIA is about ensuring what?
  • How many parts are on a DD Form 2875?
  • Which statement about token revocation lists in OAuth/OIDC is accurate?
  • How can you enforce role-based access control across multiple apps?
  • During onboarding of a new employee, which action specifically contributes to enforcing access security?
  • What is a privileged access management (PAM) concept in account management?
  • Which of the following is a listed type of user account?
  • What is the purpose of MFA in user authentication?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy