AAA

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/26

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:15 AM on 9/3/24
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

27 Terms

1
New cards

Implicit Deny

A principle stating that access requires explicit authorization and everything else is rejected.

2
New cards

Hardware Token

A "something you have" authentication factor used to access high-risk applications.

3
New cards

Rule-Based Access Control

An authorization access model in which access is based on policies that are non-discretionary.

4
New cards

RSA's SecurID Token

Provides multi-factor authentication by generating a number code synchronized to a code on a server, combined with a PIN.

5
New cards

Purpose of Authorization

To ensure that the person has the right to access a file or perform an action.

6
New cards

Tracking Users' Actions

Part of accounting in the access control system, required for non-repudiation.

7
New cards

Software Token

An authentication factor that can be stolen and replayed from a remote location.

8
New cards

Single Sign On

A service that allows logging on to multiple resources, servers, or sites using a common account and password.

9
New cards

Mandatory Access Control (MAC)

An authorization access model that has security clearance levels or compartments.

10
New cards

Single-Factor Authentication Example

A website requiring a username, a password, and a PIN number.

11
New cards

NOT a Primary Authentication Factor

Somewhere you are.

12
New cards

Passphrase

A longer version of a password.

13
New cards

Common Concern with Biometrics

The false-negative and false-positive rate.

14
New cards

Least Privilege

A principle stating that a user should be granted rights necessary to perform a job and nothing more.

15
New cards

Non-Repudiation Mechanism

A video surveillance camera that records who goes in or out of a particular area without user interaction.

16
New cards

Discretionary Access Control (DAC)

An authorization access model that emphasizes the owner's full control over the resource.

17
New cards

Role-Based Access Control (RBAC)

An authorization access model that groups users based on administrative or job functions.

18
New cards

Logging Events in an Audit Log

Part of the access control system known as accounting.

19
New cards

Non-Repudiation Mechanism for Document Authorship

A physical or digital signature.

20
New cards

Permissions

The set of rules that determines what actions you are allowed to perform on a computer and what resources you can access.

21
New cards

Security Question Response

Personally Identifiable Information (PII).

22
New cards

Configuration Change for Accountability

Preventing users from clearing web browsing history.

23
New cards

Non-Repudiation Mechanism for Account Operation

A biometric authentication device that proves a person was genuinely operating an account.

24
New cards

Multifactor Authentication Scenario

A secured room requiring a user to swipe an ID badge and then type in a PIN code.

25
New cards

Personal Identification Number (PIN)

A "something you know" authentication factor because you must remember the digits.

26
New cards

Non-Repudiation Mechanism for Product Request

A token or receipt that proves a user requested a product and that it was delivered.

27
New cards

Administrator Account

An account that grants complete access to a computer.