Domain 5 · 13%

Identity & Access Management

Quản lý Danh tính & Truy cập

Domain 5 covers every aspect of proving and controlling who can access what. Master authentication factors, access control models, SSO protocols, and the identity lifecycle.

13%

Exam Weight

Domain Progress

0 / 5 lessons complete

5 Lessons

Key Domain 5 Exam Themes

True MFA requires two DIFFERENT factor types — same type twice is not MFA.
OAuth 2.0 = authorization only; OIDC adds authentication (ID Token).
ABAC is most flexible; MAC is most restrictive; RBAC is most common in enterprise.
Leaver access must be disabled IMMEDIATELY on termination decision — not last working day.
TACACS+ encrypts entire packet; RADIUS encrypts password only.
Lower CER = more accurate biometric system.