Users Request and Provisioning Flashcards

(81 cards)

1
Q

What is #1 defining?

Quicklinks

A

Who can request for this Quicklink.

Creating a group of users for this quicklink.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is #2 defining?

Quicklinks

A

Which users can be targeted/request access for.

Creating a group of users for this quicklink.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is #3 defining?

Quicklinks

A

What can be requested (access).

Creating a group of users for this quicklink.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What can you request with #1.

A

Add or remove roles/entitlements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What can you request with #2.

A

Request, delete, modify accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What can you request with #3.

A

Changed passwords on managed systems or IdentityIQ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Important note to know about access given in Quicklinks.

A

Access is cumulative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

List possible Provisioning Policies.

A

CUUPEDD
- Create
- Update
- Unlock
- Password
- Enable
- Delete
- Disable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Where do you go to Configure Account Dependency

A

Navigate to Applications > Application Definition in the IdentityIQ UI.
Select the application for which you want to define dependencies.
Go to the Provisioning Policies tab.
Under Application Dependencies, specify the dependent applications and their required fields.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Lifecycle Event possible Event Types

A

CRAMRAN
- Create
- Rule
- Attribute Change
- Manager
- Rapid Setup
- Alert
- Native Change

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

List the IdentityIQ actions that can trigger provisioning

A

User Initiated Actions
System Initiated Actions
Lifecycle Event-Driven Provisioning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

List possible User Initiated Provisioning

A

CLAP
Certifications
Lifecycle Manager
Access Requests
Policy Violations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

List possible System Initiated Provisioning

A

BAIR
Background Reconciliation
Aggregation
Identity Refresh-Driven Assignments
Role Assignments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

List possible Lifecycle event initiated Provisioning

A

Joiner
Leaver
Manager Transfer
Reinstate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are Lifecycle Events?

A

Activities that happen in the normal course of a person’s employment
* Joining the company (joiners)
* Changing departments/managers (movers)
* Leaving the company (leavers)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe the process of Attribute Synchroniztion

A

Attribute synchronization is an automated process of synchronizing changes to Identity Cube identity attributes (such as name, email, or department) from an authoritative source to target systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Yes or No

Attribute Synchronization is Triggered by Aggregation

A

YES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Yes or No

Attribute Synchronization is Triggered by editing identity in UI.

A

Yes

Direct Edit to an Identity or Aggregation (Synchronize Attributes refresh option)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What can you create provisioning requests for in IdentityIQ?

A

Certifications,
Policy Violations,
Identity Refresh-Driven Assignments,
Lifecycle Manager Requests,
Lifecycle Event-Driven Provisioning

These actions represent different scenarios under which provisioning requests can be initiated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Fill in the blank: You can create provisioning requests in IdentityIQ using _______.

A

CLLIP
Certifications,
Lifecycle Manager Requests,
Lifecycle Event-Driven Provisioning,
Identity Refresh-Driven Assignments,
Policy Violations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Yes or No

Identity Refresh-Driven Assignments can be used to create provisioning requests in IdentityIQ.

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Yes or No

Identity Refresh-Driven Assignments can be used to create provisioning requests in IdentityIQ.

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Yes or No

Manage Access can be used to create provisioning requests in IdentityIQ.

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Yes or No

Policy Violations can be used to create provisioning requests in IdentityIQ.

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
# Yes or No Entitlements can be used to create provisioning requests in IdentityIQ.
No
26
# Yes or No Provisioning request created by a Identity refresh creates a workflow case.
Yes
27
# Yes or No Provisioning request created by a certification creates a workflow case.
No
28
# Yes or No Provisioning request created by a Lifecycle Manager Request creates a workflow case.
Yes
29
# Yes or No The owner on an Role is ususally the violation owner.
No | Manager is the correct answer
30
# Yes or No Only the remediations of roles or entitlement Non-SOD Policy Violations generate a provisioning request to revoke invalid access.
No | Only SOD policy Violations
31
# Yes or No You can create policy violation remediation requests from Lifecycle Manager
No
32
# Yes or No You can create policy violation remediation requests from Policy owner's Policy Violation page
Yes
33
# Yes or No You can create policy violation remediation requests from a certification
Yes
34
# Yes or No You have to enable the following options in an Identity Refresh to generate a provisioning request for identities. External applicatons: Provision assignments
Yes
35
# Yes or No You have to enable the following options in an Identity Refresh to generate a provisioning request for identities. Roles: Refresh assigned, detected roles and promote additional entitlements
Yes
36
# Yes or No You have to enable the following options in an Identity Refresh to generate a provisioning request for identities. External applicatons: Refresh assigned, detected roles and promote additional entitlements
No | Not for External applications
37
# Yes or No You have to enable the following options in an Identity Refresh to generate a provisioning request for identities. Roles: Provision assignments
No | Not for Roles
38
# Yes or No You have to enable the following options in an Identity Refresh to generate a provisioning request for identities. Roles: Refresh identity entitlements for all links
No | This does not generate requests
39
# Refresh assigned, detected roles and promote additional entitlements Generates provisioning requests to add entitlements required by the currently assigned roles.
Yes
40
# Lifecycle Manager Requests In a typical configuration: Managers can make requests for their direct reports.
Yes
41
# Lifecycle Manager Requests In a typical configuration: Managers can make requests for their direct reports.
Yes
42
# Lifecycle Manager Requests In a typical configuration: Managers can make requests for their direct reports.
Yes
43
# Yes or No Lifecycle Manager is a separately licensed portion of the IdentityIQ product.
Yes
44
# Yes or No Manage Accounts is designed to manage entitlements using provisioning requests
No | Lifecycle Manager
45
# Yes or No Use the Manage Accounts feature to: Unlock locked accounts
Yes
46
# Yes or No Use the Manage Accounts feature to: Add the entitlement to the specified identity
No
47
# Yes or No Use the Manage Accounts feature to: Enable disabled accounts
Yes
48
# Yes or No Use the Manage Accounts feature to: Add the entitlement to the specified identity
No
49
# Yes or No Use the Manage Accounts feature to: Request accounts on additional applications
Yes
50
# Yes or No Use the Manage Accounts feature to: Revoke an identity's current entitlements.
No | Request Entitlements
51
# Yes or No Use the Lifecycle Manager Request Access to: Revoke or disable existing accounts
No
52
# Yes or No Use the Lifecycle Manager Request Access to: Request accounts on additional applications
No
53
# Yes or No Use the Lifecycle Manager Request Access to: Provision the entitlements the role requires
Yes
54
# Yes or No Use the Lifecycle Manager Request Entitlements to: Add the entitlement to the specified identity
Yes
55
# Yes or No Use the Lifecycle Manager Request Entitlements to: Revoke an identity's current entitlements
Yes
56
# Yes or No Use the Lifecycle Manager Request Entitlements to: Provision the entitlements the role requires.
No | Request Access
57
# Yes or No Use the Lifecycle Manager Request Entitlements to: Deprovision by removing roles from an identity
No | Request Access
58
# Yes or No Use the Lifecycle Manager: Create Identity
Yes
59
# Yes or No Use the Lifecycle Manager: Manage Passwords
Yes | resets passwords on target systems which involves a provisioning plan an
60
# Yes or No With Lifecycle Manager enabled, Lifecycle Events can be configured in IdentityIQ to represent activities that occur during the normal course of a person's employment at a company.
Yes
61
# Yes or No One of the four predefined Lifecycle Events: Joiner
Yes
62
# Yes or No One of the four predefined Lifecycle Events: Mover
No | They call it Manager Transfer
63
# Yes or No One of the four predefined Lifecycle Events: Reinstate
Yes
64
# Yes or No One of the four predefined Lifecycle Events: Manager Transfer
Yes
65
# Yes or No Specific changes to an identity that will trigger Lifecycle Event: Attribute change
Yes
66
# Yes or No Specific changes to an identity that will trigger Lifecycle Event: Identity Trigger rule
Yes
67
# Yes or No The four predefined Lifecycle Events are enabled by default.
No
68
# Yes or No Default action of of Lifecycle event - Joiner is to create account
No | Prints to sysout, no actions are taken
69
# Yes or No Default action of of Lifecycle event - Reinstate is to create account
No | Reinstate is a rehire. ## Footnote Enables all previously disabled accounts of returning identity
70
# Yes or No Default action of of Lifecycle event - Leaver creates and runs provisioning plan to disable all accounts.
Yes
71
# Yes or No Only mangers and administrators can edit the Identity cube information
No | Only Administrators
72
# Yes or No Identities Warehouse: A provisioning plan is generated that updates an identity when you: **Change capabilities or assigned scopes on the User Rights tab**
Yes
73
# Yes or No Identities Warehouse: A provisioning plan is generated that updates an identity when you: **Delete or Move account links from the Application Accounts tab.**
Yes
74
# Yes or No Identities Warehouse: A provisioning plan is generated that updates an identity when you: **Add identity to workgroup**
No | Not an option in Identities Warehouse
75
# Yes or No If the triggering attributes for the identity have not changed, deleted roles that were assigned by rules are automatically reassigned to the identity during the next identity refresh.
Yes
76
# Yes or No By default, cache updates are performed every 5 minutes
No
77
# Yes or No By default, cache updates are performed every 10 minutes
Yes
78
# Yes or No When an identity’s access to a system is determined to be inappropriate for their job function, the certifier can revoke the entitlement through the Certification Access Review. This process is called Certificate Remediation.
Yes
79
# Yes or No When an identity’s access to a system is determined to be inappropriate for their job function, the certifier can revoke the entitlement through the Certification Access Review. This process is called Certificate Rejection.
No
80
# Yes or No You have to edit the xml for any policy to include remediated as one of its certificationActions values.
Yes
81
# Yes or No You have select remedication in the cerification settings GUI for any policy to include remediated as one of its Certification Actions values.
No | XML must be edit. No GUI interface