50 IAM, MFA and Zero Trust Interview Questions and Answers
This pack provides 50 IAM, MFA and Zero Trust interview Q&As: factors, SSO/SAML/OIDC themes, RBAC/ABAC, PAM, Conditional Access, machine identities and assume-breach access design — frequent in India enterprise IAM and US identity-security interviews. No bypass or fatigue-abuse recipes.
Friends! IAM + MFA + Zero Trust = today's identity interview. 'Is a password enough?' — no. 50 Q&A: factors, SSO, least privilege, assume breach. Do not experiment deny-all in a company tenant.
मित्रांनो! IAM + MFA + Zero Trust = आजची identity interview. 'Password enough आहे का?' – नाही. 50 Q&A: factors, SSO, least privilege, assume breach. Company tenant मध्ये deny-all experiment नको.
मित्रों! IAM + MFA + Zero Trust = आज की identity interview. 'Password enough है क्या?' – नहीं. 50 Q&A: factors, SSO, least privilege, assume breach. Company tenant में deny-all experiment नहीं.
How to use this pack
Explain MFA types and phishing-resistant options clearly. Use a joiner-mover-leaver story in answers. Separate workforce IAM from customer CIAM when asked. Describe break-glass without hand-waving monitoring. Map Zero Trust to concrete controls, not logos. Never practise MFA bypasses or social-engineering colleagues.
Educational / lab-only
Identity security content here is defensive. No instructions to bypass MFA, fatigue-abuse push prompts, steal tokens, or phish credentials. Test Conditional Access only in tenants you own or with change control.
IAM + MFA + Zero Trust: prove identity, elevate just enough, and verify continuously with assume-breach monitoring.
IAM + MFA + Zero Trust: identity prove करा, just enough elevate करा, आणि assume-breach monitoring सह verify continuously.
IAM + MFA + Zero Trust: identity prove करो, just enough elevate करो, और assume-breach monitoring के साथ verify continuously.
Questions 1–50
Q1. What is IAM in plain English? (Beginner)
Identity and Access Management covers how identities are created, authenticated, authorised, reviewed and retired — humans, services and devices. Good IAM shrinks breach impact more than almost any shiny box.
Q2. Authentication vs authorisation vs accounting? (Beginner)
Authn proves identity. Authz permits actions. Accounting/audit records what happened. Map the AAA model to modern IdP plus SIEM in interviews.
Q3. Four identity types to name? (Beginner)
Humans (workforce/customers), workloads/services, devices and third parties/contractors. Each needs different lifecycle and credentials. Do not share one service account for everything.
Q4. What is MFA? Factors? (Beginner)
Multi-factor means two or more categories: knowledge, possession, inherence. Password plus TOTP app, password plus hardware key, or passkeys. SMS beats nothing but is weaker against SIM swap.
Q5. Passwordless / passkeys — what to say? (Intermediate)
Passkeys (FIDO/WebAuthn) use device-bound cryptography with strong phishing-resistance properties. Plan recovery and device-loss procedures. Roll out with governance, not chaos.
Q6. MFA fatigue attacks — defence? (Intermediate)
Attackers spam push approvals until a user accepts. Defences: number matching, hardware keys, training to deny unexpected pushes, and risk-based policies. Prefer phishing-resistant MFA for admins. No fatigue-abuse how-tos.
Q7. What is SSO? (Beginner)
Single Sign-On lets one IdP login unlock many apps via SAML/OIDC. Benefits: central MFA, faster offboarding, fewer passwords. The IdP becomes a crown jewel — harden it.
Q8. SAML vs OIDC at a glance? (Intermediate)
Both federate identity. SAML (XML) is common in enterprise apps; OIDC (OAuth 2.0 identity layer, JWT) is common in modern/mobile. Know use cases, not byte dumps.
Q9. What is OAuth 2.0 used for? (Beginner)
Delegated authorisation so an app gets limited access tokens without the user password. Scopes matter. Misconfigured redirect URIs cause trouble — defend carefully.
Q10. Access token vs refresh token themes? (Intermediate)
Access tokens are short-lived for API calls; refresh tokens obtain new access tokens and need tighter storage. Stolen refresh tokens mean longer abuse — protect like passwords.
Q11. What is RBAC? (Beginner)
Role-Based Access Control assigns permissions to roles, then users to roles. Scales better than per-user ACLs. Review role definitions — admin creep is common.
Q12. What is ABAC? (Intermediate)
Attribute-Based Access Control uses attributes (department, data class, environment) in policies. Powerful in cloud IAM conditions. Needs clean attribute data.
Q13. Least privilege lifecycle? (Beginner)
Joiners get minimal roles; movers change access with tickets; leavers lose access same day. Recertify privileged access quarterly. Orphan accounts fuel breaches.
Q14. Privileged Access Management (PAM) idea? (Intermediate)
Vault admin credentials, just-in-time elevation, session recording and dual control for break-glass. Standing domain admin is a bad default.
Q15. Service accounts / machine identity risks? (Beginner)
Non-human identities often have long-lived secrets and unclear owners. Prefer workload identity federation, short-lived creds, rotation and secret scanning. Map owners.
Q16. Zero Trust pillars you should recite? (Beginner)
Verify explicitly, least privilege access, assume breach. Practically: strong identity, device health, app-level access, segmentation, continuous monitoring. Not a single SKU.
Q17. Zero Trust vs VPN flat access? (Intermediate)
Classic VPN often places users on a broad segment. Zero Trust aims for per-request, per-app authorisation with context. Hybrid migration is normal.
Q18. Device trust / posture — why? (Beginner)
Check disk encryption, patch level and EDR health before sensitive apps. A stolen password on an unmanaged phone should not equal full ERP access.
Q19. Conditional Access / risk-based policies? (Intermediate)
IdP policies that require MFA, block legacy auth or challenge odd locations/devices. Start report-only when possible to avoid lockouts. Monitor break-glass exclusions carefully.
Q20. Legacy authentication — why disable? (Intermediate)
Old protocols often bypass modern MFA. Attackers prefer them for password sprays. Disable where business allows after providing modern clients.
Q21. Password policy modern view? (Beginner)
Length and blocklisted breached passwords beat frequent forced rotation without cause (many cite NIST-aligned guidance). Always combine with MFA. Encourage password managers.
Q22. How should admins authenticate? (Beginner)
Separate admin accounts, phishing-resistant MFA (keys/passkeys), limited browsing on admin sessions per policy, and just-in-time elevation. Never reuse admin passwords elsewhere.
Q23. Offboarding checklist identity items? (Beginner)
Disable IdP account, revoke sessions/tokens, remove groups/roles, collect tokens/smartcards, transfer service-account ownership, verify VPN/MDM wipe. Same-day for high risk.
Q24. Access reviews / certifications? (Beginner)
Managers periodically attest who still needs access. Automate reminders; remove no-responses per policy. Critical for regulated US firms and India captives alike.
Q25. JIT / just enough admin? (Intermediate)
Elevate for a ticket window, then expire. Reduces standing privilege. Pair with change tickets and session audit.
Q26. Identity threat detection signals? (Intermediate)
Impossible travel, MFA anomalies, sudden consent grants, new forwarding rules, privilege escalations and mass download patterns. Feed IdP logs to SIEM.
Q27. SCIM provisioning — why care? (Intermediate)
Automates join/move/leave into apps from the IdP. Reduces orphan accounts versus spreadsheets. Still monitor failed deprovisions.
Q28. Customer IAM vs workforce IAM? (Beginner)
Workforce: employees/contractors into internal apps. Customer CIAM: users of your product — different scale, consent and bot abuse. Do not mix admin planes casually.
Q29. API keys as identities — hygiene? (Beginner)
Treat as secrets: least scope, rotation, environment separation, never as sole auth in mobile apps. Prefer user tokens plus backend secrets.
Q30. Certificate-based auth themes? (Intermediate)
Device or user certs for VPN/Wi-Fi/802.1X. Protect private keys in TPM/HSM when possible; manage lifecycle and revocation.
Q31. What is a permission boundary (AWS-shaped)? (Intermediate)
A guardrail limiting maximum permissions a principal can receive even if a broader policy is attached. Lets teams create roles without creating admins.
Q32. Explain segregation of duties (SoD). (Beginner)
Split powers so one person cannot create fraud alone — developer ≠ production deployer ≠ payment approver. Enforce with roles and approvals.
Q33. Zero Trust policy engine idea? (Intermediate)
Central decisions evaluate identity, device, location and app sensitivity per request. Enforcement at proxies/gateways/agents. Start with high-value apps.
Q34. How Zero Trust handles lateral movement? (Beginner)
By not trusting network location: micro-segmentation, identity-aware access and continuous monitoring. A compromised laptop should not freely RDP everywhere.
Q35. Break-glass account rules? (Beginner)
Stored securely, MFA, alert on any use, periodically tested, post-use review. Exclude from casual Conditional Access only with compensating controls.
Q36. Session revocation — when? (Beginner)
After phishing suspicion, employee exit, device loss or privilege change. Revoke IdP and SaaS sessions and reset passwords. Practise the clicks before incidents.
Q37. Consent phishing / OAuth app grants? (Intermediate)
Users approve malicious apps requesting scopes. Defend with admin consent workflows, scope review and education. Monitor new high-privilege grants. No phishing recipes.
Q38. Directory services — AD vs cloud IdP? (Beginner)
AD anchors many on-prem apps; cloud IdPs anchor SaaS. Hybrid sync introduces crown jewels — harden sync accounts and federation.
Q39. Kerberos basics for interviews? (Intermediate)
Ticket-based auth in AD environments. Defenders focus on tiering, DC patching, monitoring unusual TGT patterns and least privilege — not attack how-tos for ticket abuse.
Q40. Privileged tier model (AD)? (Intermediate)
Separate Tier 0 identity systems from Tier 1 servers and Tier 2 workstations; no casual browsing from Tier 0 admin sessions. Reduces credential-theft impact.
Q41. Password managers — enterprise angle? (Beginner)
Encourage unique passwords; prefer enterprise vaults with SSO and audit. Protect break-glass to the vault itself. Discourage password spreadsheets.
Q42. Identity for CI/CD? (Beginner)
OIDC to cloud roles, short-lived tokens, branch protections, no shared human creds in pipelines. Rotate on staff changes.
Q43. Measuring IAM maturity? (Intermediate)
MFA coverage percent, standing admin count, time-to-revoke, orphan accounts and percent of apps on SSO. Trends beat one-time audits.
Q44. Zero Trust implementation pitfalls? (Beginner)
Big-bang lockouts, ignoring break-glass, buying tools without identity hygiene, and no logging. Start with MFA plus SSO plus device compliance on critical apps.
Q45. Explain Zero Trust to a non-tech CIO? (Beginner)
We stop treating inside-the-network as safe. Every access asks who you are, whether the device is healthy, and whether you need this app now — then we log it. That shrinks ransomware blast radius.
Q46. India + US company interview expectation? (Beginner)
Expect scenarios: contractor offboarding, MFA rollback, Conditional Access lockout recovery, least privilege versus ticket urgency. Speak risk language, not tool fanboyism.
Q47. What is identity governance (IGA)? (Intermediate)
Processes and tools for access requests, approvals, certifications and role modelling. Bridges HR events to IT access. Important in regulated firms.
Q48. Recovery codes / backup MFA — risks? (Beginner)
Store offline securely; treat like passwords; monitor use. Attackers who phish passwords may also social-engineer recovery. Prefer hardware keys for admins.
Q49. How do you test IAM changes safely? (Beginner)
Non-prod first, report-only policies, staged rollouts and monitored break-glass. Never experiment deny-all on production SSO without change control.
Q50. Closing: IAM + MFA + Zero Trust together? (Beginner)
IAM defines who; MFA hardens proof; Zero Trust continuously decides access with least privilege and assume-breach monitoring. Together they beat perimeter-only thinking for modern India and US enterprises.
Ravindra Bagale's Tip
💡 Students bury Zero Trust in product names. The interviewer asks: 'VIP phished yesterday — then what?' — session revoke, MFA reset, device posture, ticket. Process > buzzword. Got the discipline?
Ravindra Bagale's Tip – मराठी
💡 Students Zero Trust ला product नाव मध्ये ओढतात. Interviewer विचारतो: 'काल VIP phish झाला तर काय?' — session revoke, MFA reset, device posture, ticket. Process > buzzword. समजलं का discipline?
Ravindra Bagale's Tip – हिंदी
💡 Students Zero Trust को product नाम में घसीटते हैं. Interviewer पूछता है: 'कल VIP phish हुआ तो क्या?' — session revoke, MFA reset, device posture, ticket. Process > buzzword. समझ में आई discipline?
Related guides on this site
Got it? IAM who, MFA proof, Zero Trust continuous least privilege. Practise the 50 Q out loud. Next revise basics/SOC/network/cloud packs — panels mix topics.
समजलं का? IAM who, MFA proof, Zero Trust continuous least privilege. 50 Q बोलून तयार. पुढे basics/SOC/network/cloud packs revise करा — panels mix topics.
समझ में आया? IAM who, MFA proof, Zero Trust continuous least privilege. 50 Q बोलकर तैयार. आगे basics/SOC/network/cloud packs revise करो — panels mix topics.
Frequently asked questions
Is Zero Trust a product?
No. It is a strategy: verify explicitly, least privilege, assume breach — implemented with identity, device and network controls.
Why is SMS MFA weaker?
SIM-swap and interception themes; prefer authenticator apps or hardware keys for admins.
What is MFA fatigue defence?
Number matching, hardware keys, user deny training and risk policies — not push spam how-tos.
How do Conditional Access lockouts happen?
Over-tight policies without break-glass or report-only staging. Test in non-prod first.
Machine identity vs human identity?
Workloads need short-lived federation and owners; humans need MFA and lifecycle reviews.
Related guides on this site?
Zero Trust explained, enable MFA, cloud IAM least privilege and machine identity guides.