Repair an employee's grants and cached service access
A hands-on CISSP lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.
Try this labAll CISSP practice
- Certification
- CISSP
- Format
- Structured configuration
- Difficulty
- medium
- Estimated time
- 30 min
- Automated checks
- 9
The brief
Edit identity-plan.json. grants needs unique id, kind (role or permission), target, window ([from,to]) and approval ID. A grant must fit its exact immutable approval, and every active permission including inherited/direct access must fit the current employment phase. Retire old memberships and direct grants at the move; remove all grants at departure. serviceModes needs one {id,mode} for ledger and reports, with mode snapshot or online. Snapshot services use each valid token's immutable issued claims plus its revocation time, and do not independently read employment/directory state. Online services use a valid token but check current employment and current directory permissions on every request; the modeled online service is available, authoritative and uncached. Directory changes alone do not change snapshot claims. Permissions visible at a service are intersected with that service's supported permissions and unioned across every usable token. tokenActions is a nondecreasing slot ledger with distinct id, op, slot, actor and token. issue also needs expires. Issuance requires an employed subject, unused token ID, authorized actor and at most 8 slots of validity; it snapshots all directory permissions active at that issue slot. revoke requires an existing issued token that has not already been revoked, and an authorized actor. Failed operations have no token effect; grants themselves remain modeled even when authority/lifecycle checks fail separately. Future tokens cannot be used before issuance. Provide all required operations throughout each phase while preventing other permissions, incompatible duties and any service access from slot 11. Choose online current authorization or explicit snapshot token replacement/revocation; do not manufacture a new approval or merely rename a privileged role.
What the checks verify
Your work is graded on 9 independent properties, not on matching one reference answer.
- Typed distinct grants, token actions and service modes.
- Each entitlement fits its exact delegated approval.
- Every grant ends when its employment purpose ends.
- Token actions are feasible, chronological and delegated.
- Actual usable service access stays inside phase permissions.
- No directory or usable service portfolio combines incompatible duties.
- Finance operations remain usable at each pre-move demand.
- Reviewer operations remain usable through the review phase.
- All service access ends at the departure boundary.
Where this sits in the CISSP blueprint
- Domain
- Identity and Access Management (IAM)
- Objective
- Identity Provisioning Lifecycle
- Skill
- Joiners, Movers, Leavers and Reviews
Part of CISSP preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.