Most modern intrusions involve stolen or misused credentials, so identity is often called the new perimeter. An attacker who logs in with a valid account looks, at first glance, like a normal user, which is why identity controls and the logs they produce are central to an analyst's work. For CySA+ you need to know how each identity control works, which threat it counters, what its logs look like and which weaknesses attackers target.
Multifactor authentication (MFA) requires factors from at least two different categories: something you know (a password or PIN), something you have (a phone, hardware token or smart card) and something you are (a fingerprint or face). Two passwords are still one factor. Not all MFA is equal. Codes sent by SMS can be intercepted through SIM swapping, and push notifications can be abused through MFA fatigue, where an attacker who already has the password sends repeated prompts until the user approves one. Number matching reduces fatigue attacks, and phishing-resistant methods such as FIDO2 security keys or passkeys bind the login to the genuine site, so a fake site cannot relay them. In logs, watch for many denied prompts followed by an approval, or a new MFA device registered right after a suspicious login.
Single sign-on (SSO) lets a user authenticate once and reach many applications. Federation extends that trust across organizations or domains: an identity provider (IdP) authenticates the user and sends a signed assertion or token to a service provider (SP), which trusts the IdP instead of storing its own passwords. Security Assertion Markup Language (SAML) is common for enterprise web apps, OAuth 2.0 handles delegated authorization (letting an app act on your behalf without your password), and OpenID Connect (OIDC) adds an authentication layer on top of OAuth. SSO reduces password reuse and centralizes logging and account disabling, but it also makes the IdP a high-value target, because one stolen session token can open many doors.
Privileged access management (PAM) protects administrator, root and service accounts. A PAM system vaults credentials, rotates them automatically, requires check-out with approval, records privileged sessions and can inject credentials without revealing them to the user. Just-in-time (JIT) access removes standing privilege: a user requests elevation for a specific task and time window, and the rights disappear automatically afterward. A cloud access security broker (CASB) sits between users and cloud services to provide visibility and control. It discovers shadow IT (unsanctioned apps), enforces policies such as blocking uploads of sensitive data, detects risky behavior and checks compliance, working through API connections to sanctioned services, inline proxies, or both.
Consider a worked example. At 02:14 an analyst sees 25 declined MFA push prompts for a finance user, followed at 02:41 by one approval from the same unfamiliar country. Minutes later the mailbox gains a rule forwarding messages containing 'invoice' to an external address. The pattern is MFA fatigue after password theft. The response is to disable the account, revoke active sessions and refresh tokens, reset the password, remove the forwarding rule and any newly registered MFA devices, and review what was accessed. Longer term, the organization moves finance staff to number matching or FIDO2 keys and alerts on bursts of denied prompts.
Common mistakes: counting a password plus a security question as MFA (both are something you know); assuming SSO itself is a security weakness rather than recognizing it concentrates risk in the IdP; confusing OAuth, which is authorization, with authentication; believing a password reset alone ends an incident, when stolen session tokens may still be valid; and treating PAM and JIT as the same thing. PAM manages and monitors privileged credentials, while JIT is about granting privilege only when needed. They work well together.
Exam questions often name a threat and ask for the matching control. 'Password theft' or 'credential stuffing' points to MFA; 'repeated push prompts' points to MFA fatigue and a fix such as number matching or phishing-resistant MFA. 'Users have too many passwords' points to SSO; 'trust between two organizations' points to federation. 'Eliminate standing admin rights' points to just-in-time access, while 'vault, rotate and record admin sessions' points to PAM. 'Shadow IT' or 'control data going to cloud apps' points to a CASB. If two answers both seem reasonable, pick the one that removes the specific weakness the scenario describes.
Key terms
- MFA
- Multifactor authentication, which requires factors from at least two different categories: know, have and are.
- MFA fatigue
- An attack in which repeated push prompts are sent until a tired or confused user approves one.
- Federation
- A trust relationship in which a service provider accepts identity assertions from an external identity provider.
- OpenID Connect
- An authentication layer built on OAuth 2.0 that tells an application who the user is.
- PAM
- Privileged access management, which vaults, rotates, controls and records use of high-privilege accounts.
- Just-in-time access
- Granting elevated rights only for a specific task and time window, then removing them automatically.
- CASB
- Cloud access security broker, a control point that gives visibility and policy enforcement over cloud service use.
An analyst sees 25 declined MFA push prompts for a finance user between 2 and 3 a.m., then one approval, then a new mailbox rule forwarding invoices to an outside address. The account is disabled, sessions and tokens revoked, the password reset and the rule removed. The organization then moves finance staff to number matching and FIDO2 keys and adds a SIEM alert for bursts of denied prompts.
Check yourself
Why is a password plus a PIN not multifactor authentication?
Both are something you know, so they come from the same factor category.
What log pattern suggests an MFA fatigue attack?
Many denied or ignored push prompts in a short period, followed by an approval, often at an odd hour or from an unusual location.
In federation, which party authenticates the user and which party trusts the result?
The identity provider authenticates the user; the service provider trusts the signed assertion or token it receives.
Which control would discover employees using unsanctioned cloud file-sharing apps?
A cloud access security broker (CASB), which provides shadow IT discovery and cloud usage policy enforcement.