Question 1
How would you enforce device compliance before granting access?
Correct Answer:
Device health checks, endpoint management, device inventory, patch status, MDM/EMM.
Explanation:
Enforcing device compliance before granting access hinges on evaluating the device’s posture through a set of managed checks. By performing device health checks, you verify that the device is operating normally and free from known issues. Endpoint management and device inventory confirm the device is enrolled, known, and under IT control, so it can be enforced with policies. Patch status ensures the device has current security updates, reducing vulnerability to exploits. MDM/EMM provides the framework to apply and enforce security configurations, such as encryption, passcodes, app controls, and allowed OS versions, and can block access or remediate if noncompliant. When all these criteria are met, access is granted only to devices that meet the security requirements, reflecting a zero-trust approach where trust is based on verified device posture. Relying on any single factor like allowing any device, only requiring a password, or checking location alone does not verify the necessary security state and would leave gaps that attackers could exploit.
Question 2
Which practice is consistent with minimizing risk in identity management?
Correct Answer:
Storing credentials in plain text in spreadsheets.
Explanation:
Centralizing identity management and automating provisioning across apps reduces risk by ensuring that access is controlled from one authoritative source and applied consistently everywhere. When roles and permissions are defined in a central identity provider and pushed to connected applications through standards like SCIM or provisioning connectors, changes such as hiring, role changes, or terminations are reflected everywhere in a timely, uniform way. This supports least privilege, reduces the chance of stale or conflicting permissions, and makes auditing and revocation much more reliable. Storing credentials in plain text in spreadsheets is a serious security flaw, exposing sensitive data to leaks or misuse. Using multiple central identity providers with inconsistent roles creates governance gaps and drift in access control. Disabling RBAC removes a foundational mechanism for controlling who can do what across systems, increasing risk dramatically.
Question 3
Why is device-based conditional access important?
Correct Answer:
It reduces risk by allowing access only from compliant, managed devices.
Explanation:
Device-based conditional access gates access to resources based on the security status of the endpoint. When a device is enrolled in management and passes posture checks—such as being encrypted, having a current OS, a valid passcode, and not being jailbroken or rooted—it’s considered compliant and allowed to access corporate apps and data. If it isn’t compliant, access can be blocked or restricted or require remediation first. This approach reduces risk by ensuring sensitive resources aren’t exposed to insecure or unmanaged devices, tying access to both who you are and the trustworthiness of the device you’re using. It also aligns with a Zero Trust mindset, where access decisions consider device health alongside user identity. Other options don’t fit as well because device-based conditional access doesn’t mandate that all devices share the same OS version, and it doesn’t remove the need for MFA or passwords. MFA and credentials may still be required; device compliance enhances risk-based access rather than replacing authentication.
Question 4
Which statement about multifactor authentication (MFA) is true?
Correct Answer:
Adds a second factor to verify identity, mitigating password-only compromises.
Explanation:
Using multiple verification factors strengthens login security by not relying on a single credential. Multifactor authentication combines at least two different types of factors: something you know (a password), something you have (a code from a phone or a hardware token), or something you are (biometrics). The statement that MFA adds a second factor to verify identity, helping protect against password-only compromises, captures this idea: even if a password is stolen, the attacker still needs the additional factor to gain access. MFA does not replace passwords entirely; in most setups the password remains the first factor and a second factor is added. It also doesn’t require biometrics for everyone in every case—many implementations use a code from a smartphone or a hardware token instead. And it doesn’t make password complexity irrelevant—strong passwords are still important, but MFA adds an extra barrier that greatly reduces risk from password theft.
Question 5
PKI stands for?
Correct Answer:
Public Key Infrastructure
Explanation:
PKI stands for Public Key Infrastructure, a framework that uses public-key cryptography to issue, manage, and revoke digital certificates that bind public keys to identities. This system enables trusted communications by letting others verify who you are, encrypt data for you, and ensure message integrity. At its core, a certificate ties a public key to a real-world identity, and it’s issued by a trusted Certification Authority. Supporting pieces like a Registration Authority helps verify identities, and mechanisms such as Certificate Revocation Lists or OCSP handle revocation when a certificate should no longer be trusted. The other phrases aren’t standard terms for this concept, so they don’t describe the established framework for managing keys and trust. Public Key Infrastructure.
Question 1
Exam overview

About this Exam

Prepare with the Perform User Account Management Phase 1 Practice Test practice quiz. This question bank includes 10 questions covering access, device, compliance, perform, and user. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Perform User Account Management Phase 1 Practice Test

This practice set contains 10 questions from the matching question bank and focuses on access, device, compliance, perform, and user. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions