MFA & step-up
Combine independent factors (TOTP, WebAuthn/FIDO2, push approval). Step-up authentication re-challenges when risk signals rise (new device, impossible travel).
CISSP Mastery · Module 5 / 8
The perimeter is dead; Identity is the new firewall. Master the AAA framework and access control models.
Your progress
Domain 5 of 8 63%
13%
Exam weight
AAA
Foundation
5 / 8
Domain focus
PDP/PEP
Policy engine
Open preview · Domain overview
Every breach narrative eventually lands on a credential, a role, or a broken authorization path. Domain 5 trains you to engineer identity as a system: AAA, policy engines (PDP/PEP), access models from MAC to ABAC, modern authentication, and lifecycle discipline from joiner to leaver.
Domain 5 turns identity into an engineering discipline: AAA, access models, modern authentication, and lifecycle governance. Pair it with Domain 4 (where traffic flows) and Domain 6–7 (how you verify and operate controls).
AAA is the spine
Identification, authentication, authorization, and accounting — if one link is weak, the rest are theatre.
Models map to risk
MAC, DAC, RBAC, and ABAC each trade flexibility for assurance. The exam tests which model fits which regulatory reality.
Authentication ≠ authorization
Strong MFA with sloppy RBAC still loses. Most real-world failures are authorization and governance gaps, not password guessing.
Lifecycle is governance
Provisioning, periodic access review, and de-provisioning are where least privilege lives or dies in production.
Quick check
One question at a time — instant feedback. Pair it with the diagrams and Pro-Tip callouts above.
Quiz progress
Question 1 of 5
1.Which protocol is primarily used for federated SSO assertions in many enterprises?
Exam Pro-Tip
Pro-Tip: SAML is a federation standard for exchanging authentication/authorization assertions.
2.OAuth 2.0 is best described as a framework for:
Exam Pro-Tip
Pro-Tip: OAuth grants scoped access without sharing user credentials directly.
3.In Joiner-Mover-Leaver, the MOST critical first action for leavers is:
Exam Pro-Tip
Pro-Tip: Delays in offboarding create immediate exposure windows.
4.Which control most directly addresses privilege creep?
Exam Pro-Tip
Pro-Tip: Recertification and cleanup workflows keep entitlement drift under control.
5.ABAC decisions are made using:
Exam Pro-Tip
Pro-Tip: ABAC supports fine-grained, context-aware authorization policies.
Your score: 0 / 5
Module 5 is the IAM core — AAA, federation, lifecycle, and access models that appear in nearly every vignette. Keep moving through the blueprint at your pace. Domain content is free throughout; the paywall only appears on the Final Mock Exam after your free trial questions.