Topic module

Federation, Provisioning and Identity Lifecycle

This topic covers identity federation, single sign-on, credential management, directory services, provisioning, deprovisioning, access review, just-in-time access, and identity governance.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for CISSP

Treat each CISSP question as a risk decision: identify the owner, objective, control type, lifecycle phase, and business consequence before choosing.

Core concepts

Concept 1

Federation, Provisioning and Identity Lifecycle questions test whether a security leader can choose a defensible control, process, or governance response for a business risk.

Exam cue: Identify the domain objective: govern risk, protect assets, engineer securely, secure networks, control identity, test, operate, or secure software.

Concept 2

The best CISSP answer usually protects people, policy, data, and mission before jumping to a narrow technical fix.

Exam cue: Match the response to the risk owner, data owner, control objective, lifecycle phase, and assurance evidence in the scenario.

Concept 3

Eliminate answers that skip authorization, ignore legal or contractual duties, weaken least privilege, or confuse preventive, detective, and corrective controls.

Exam cue: Prefer documented policy, due care, defense in depth, least privilege, validated recovery, and continuous improvement.

Risk pitfalls and guardrails

Choosing a tool before confirming business requirements, ownership, and risk treatment.

Guardrail: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.

Treating confidentiality as the only goal when integrity, availability, authenticity, accountability, and safety also matter.

Guardrail: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.

Ignoring legal, regulatory, contractual, audit, and evidence-handling obligations.

Guardrail: Avoid answers that jump to a tool, ignore the risk owner, weaken least privilege, skip evidence, or treat one security objective as the only concern.

Memory anchors

Federation

Federation allows one organization to trust identity assertions from another identity provider.

SSO

Single sign-on lets users authenticate once and access multiple relying services.

SAML

SAML exchanges authentication and authorization assertions between identity and service providers.

OAuth

OAuth delegates authorization so an application can access resources without sharing the user's password.

OIDC

OpenID Connect adds identity authentication on top of OAuth 2.0 flows.

Provisioning

Provisioning creates or updates accounts, roles, attributes, and entitlements for users.

Deprovisioning

Deprovisioning removes or disables access when duties change or employment ends.

Access Review

Access reviews verify that current privileges remain appropriate and authorized.

JIT Access

Just-in-time access grants temporary privileges for approved tasks and then removes them.

Credential Vault

A credential vault stores and rotates secrets to reduce direct exposure.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A partner employee signs in at the partner and accesses the company's application without receiving a separate company password. Which capability is being used?

Before accepting a new identity provider, what should a relying application determine FIRST?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.