IAM & Access Control interview questions

45 IAM & Access Control questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Least privilege?

Junior
  1. A.list specifying which subjects may access a resource and what operations they may perform
  2. B.Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment
  3. C.controls and tools for securing, monitoring, and auditing privileged accounts
  4. D.granting only the minimum permissions needed to perform a task

Answer + AI explanation with Pro

2. Which term means: "granting only the minimum permissions needed to perform a task"?

Junior
  1. A.Privileged Access Management (PAM)
  2. B.Identity
  3. C.Least privilege
  4. D.Policy as code

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Least privilege — periodic review where managers re-attest that users still need their granted access
  2. B.Least privilege — controls and tools for securing, monitoring, and auditing privileged accounts
  3. C.Least privilege — granting only the minimum permissions needed to perform a task
  4. D.Least privilege — RBAC assigns access via static roles; ABAC evaluates dynamic attributes and policies at request time

Answer + AI explanation with Pro

4. What is RBAC?

Junior
  1. A.splitting critical tasks across multiple people so no single individual can commit fraud alone
  2. B.Role-Based Access Control granting permissions to roles that users are assigned to
  3. C.periodic review where managers re-attest that users still need their granted access
  4. D.expressing authorization rules in versioned, testable code (e.g. OPA/Rego)

Answer + AI explanation with Pro

5. Which term means: "Role-Based Access Control granting permissions to roles that users are assigned to"?

Junior
  1. A.RBAC
  2. B.Identity
  3. C.Mandatory Access Control (MAC)
  4. D.Access certification

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.RBAC — granting elevated permissions only temporarily for a specific task, then revoking them
  2. B.RBAC — controls and tools for securing, monitoring, and auditing privileged accounts
  3. C.RBAC — periodic review where managers re-attest that users still need their granted access
  4. D.RBAC — Role-Based Access Control granting permissions to roles that users are assigned to

Answer + AI explanation with Pro

7. What is Access Control List (ACL)?

Junior
  1. A.periodic review where managers re-attest that users still need their granted access
  2. B.creating and granting accounts and access rights to identities
  3. C.elevated rights (e.g. admin/root) that require stronger controls and monitoring
  4. D.list specifying which subjects may access a resource and what operations they may perform

Answer + AI explanation with Pro

8. Which term means: "list specifying which subjects may access a resource and what operations they may perform"?

Junior
  1. A.RBAC vs ABAC
  2. B.Access certification
  3. C.Policy as code
  4. D.Access Control List (ACL)

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Access Control List (ACL) — list specifying which subjects may access a resource and what operations they may perform
  2. B.Access Control List (ACL) — granting only the minimum permissions needed to perform a task
  3. C.Access Control List (ACL) — periodic review where managers re-attest that users still need their granted access
  4. D.Access Control List (ACL) — elevated rights (e.g. admin/root) that require stronger controls and monitoring

Answer + AI explanation with Pro

10. What is Identity?

Junior
  1. A.representation of a user, service, or device that can be authenticated and authorized
  2. B.Role-Based Access Control granting permissions to roles that users are assigned to
  3. C.list specifying which subjects may access a resource and what operations they may perform
  4. D.Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment

Answer + AI explanation with Pro

11. Which term means: "representation of a user, service, or device that can be authenticated and authorized"?

Junior
  1. A.Identity
  2. B.Just-in-time access
  3. C.Policy as code
  4. D.Access Control List (ACL)

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Identity — Role-Based Access Control granting permissions to roles that users are assigned to
  2. B.Identity — list specifying which subjects may access a resource and what operations they may perform
  3. C.Identity — controls and tools for securing, monitoring, and auditing privileged accounts
  4. D.Identity — representation of a user, service, or device that can be authenticated and authorized

Answer + AI explanation with Pro

13. What is Provisioning?

Junior
  1. A.Role-Based Access Control granting permissions to roles that users are assigned to
  2. B.granting only the minimum permissions needed to perform a task
  3. C.expressing authorization rules in versioned, testable code (e.g. OPA/Rego)
  4. D.creating and granting accounts and access rights to identities

Answer + AI explanation with Pro

14. Which term means: "creating and granting accounts and access rights to identities"?

Junior
  1. A.ABAC
  2. B.Provisioning
  3. C.Privileged access
  4. D.Deprovisioning

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Provisioning — creating and granting accounts and access rights to identities
  2. B.Provisioning — Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment
  3. C.Provisioning — representation of a user, service, or device that can be authenticated and authorized
  4. D.Provisioning — expressing authorization rules in versioned, testable code (e.g. OPA/Rego)

Answer + AI explanation with Pro

16. What is Deprovisioning?

Junior
  1. A.Role-Based Access Control granting permissions to roles that users are assigned to
  2. B.granting elevated permissions only temporarily for a specific task, then revoking them
  3. C.promptly revoking access and disabling accounts when no longer needed (e.g. offboarding)
  4. D.controls and tools for securing, monitoring, and auditing privileged accounts

Answer + AI explanation with Pro

17. Which term means: "promptly revoking access and disabling accounts when no longer needed (e.g. offboarding)"?

Junior
  1. A.Privileged Access Management (PAM)
  2. B.Deprovisioning
  3. C.Privileged access
  4. D.ABAC

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.Deprovisioning — promptly revoking access and disabling accounts when no longer needed (e.g. offboarding)
  2. B.Deprovisioning — granting only the minimum permissions needed to perform a task
  3. C.Deprovisioning — periodic review where managers re-attest that users still need their granted access
  4. D.Deprovisioning — RBAC assigns access via static roles; ABAC evaluates dynamic attributes and policies at request time

Answer + AI explanation with Pro

19. What is ABAC?

Mid
  1. A.elevated rights (e.g. admin/root) that require stronger controls and monitoring
  2. B.Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment
  3. C.granting elevated permissions only temporarily for a specific task, then revoking them
  4. D.creating and granting accounts and access rights to identities

Answer + AI explanation with Pro

20. Which term means: "Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment"?

Mid
  1. A.RBAC
  2. B.Access Control List (ACL)
  3. C.Privileged access
  4. D.ABAC

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.ABAC — Role-Based Access Control granting permissions to roles that users are assigned to
  2. B.ABAC — Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment
  3. C.ABAC — controls and tools for securing, monitoring, and auditing privileged accounts
  4. D.ABAC — representation of a user, service, or device that can be authenticated and authorized

Answer + AI explanation with Pro

22. What is Separation of duties?

Mid
  1. A.splitting critical tasks across multiple people so no single individual can commit fraud alone
  2. B.Role-Based Access Control granting permissions to roles that users are assigned to
  3. C.controls and tools for securing, monitoring, and auditing privileged accounts
  4. D.expressing authorization rules in versioned, testable code (e.g. OPA/Rego)

Answer + AI explanation with Pro

23. Which term means: "splitting critical tasks across multiple people so no single individual can commit fraud alone"?

Mid
  1. A.Identity
  2. B.ABAC
  3. C.Separation of duties
  4. D.RBAC vs ABAC

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Separation of duties — splitting critical tasks across multiple people so no single individual can commit fraud alone
  2. B.Separation of duties — expressing authorization rules in versioned, testable code (e.g. OPA/Rego)
  3. C.Separation of duties — controls and tools for securing, monitoring, and auditing privileged accounts
  4. D.Separation of duties — periodic review where managers re-attest that users still need their granted access

Answer + AI explanation with Pro

25. What is Privileged access?

Mid
  1. A.elevated rights (e.g. admin/root) that require stronger controls and monitoring
  2. B.expressing authorization rules in versioned, testable code (e.g. OPA/Rego)
  3. C.granting elevated permissions only temporarily for a specific task, then revoking them
  4. D.Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment

Answer + AI explanation with Pro

26. Which term means: "elevated rights (e.g. admin/root) that require stronger controls and monitoring"?

Mid
  1. A.Deprovisioning
  2. B.Access Control List (ACL)
  3. C.Privileged access
  4. D.Mandatory Access Control (MAC)

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Privileged access — representation of a user, service, or device that can be authenticated and authorized
  2. B.Privileged access — list specifying which subjects may access a resource and what operations they may perform
  3. C.Privileged access — elevated rights (e.g. admin/root) that require stronger controls and monitoring
  4. D.Privileged access — system-enforced access based on labels/clearances that users cannot override

Answer + AI explanation with Pro

28. What is RBAC vs ABAC?

Mid
  1. A.splitting critical tasks across multiple people so no single individual can commit fraud alone
  2. B.controls and tools for securing, monitoring, and auditing privileged accounts
  3. C.RBAC assigns access via static roles; ABAC evaluates dynamic attributes and policies at request time
  4. D.list specifying which subjects may access a resource and what operations they may perform

Answer + AI explanation with Pro

29. Which term means: "RBAC assigns access via static roles; ABAC evaluates dynamic attributes and policies at request time"?

Mid
  1. A.Policy as code
  2. B.Identity
  3. C.Just-in-time access
  4. D.RBAC vs ABAC

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.RBAC vs ABAC — granting elevated permissions only temporarily for a specific task, then revoking them
  2. B.RBAC vs ABAC — RBAC assigns access via static roles; ABAC evaluates dynamic attributes and policies at request time
  3. C.RBAC vs ABAC — system-enforced access based on labels/clearances that users cannot override
  4. D.RBAC vs ABAC — Attribute-Based Access Control deciding access from attributes of subject, resource, action, and environment

Answer + AI explanation with Pro

Showing 30 of 45 IAM & Access Control questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every IAM & Access Control question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers