1/26
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Implicit Deny
A principle stating that access requires explicit authorization and everything else is rejected.
Hardware Token
A "something you have" authentication factor used to access high-risk applications.
Rule-Based Access Control
An authorization access model in which access is based on policies that are non-discretionary.
RSA's SecurID Token
Provides multi-factor authentication by generating a number code synchronized to a code on a server, combined with a PIN.
Purpose of Authorization
To ensure that the person has the right to access a file or perform an action.
Tracking Users' Actions
Part of accounting in the access control system, required for non-repudiation.
Software Token
An authentication factor that can be stolen and replayed from a remote location.
Single Sign On
A service that allows logging on to multiple resources, servers, or sites using a common account and password.
Mandatory Access Control (MAC)
An authorization access model that has security clearance levels or compartments.
Single-Factor Authentication Example
A website requiring a username, a password, and a PIN number.
NOT a Primary Authentication Factor
Somewhere you are.
Passphrase
A longer version of a password.
Common Concern with Biometrics
The false-negative and false-positive rate.
Least Privilege
A principle stating that a user should be granted rights necessary to perform a job and nothing more.
Non-Repudiation Mechanism
A video surveillance camera that records who goes in or out of a particular area without user interaction.
Discretionary Access Control (DAC)
An authorization access model that emphasizes the owner's full control over the resource.
Role-Based Access Control (RBAC)
An authorization access model that groups users based on administrative or job functions.
Logging Events in an Audit Log
Part of the access control system known as accounting.
Non-Repudiation Mechanism for Document Authorship
A physical or digital signature.
Permissions
The set of rules that determines what actions you are allowed to perform on a computer and what resources you can access.
Security Question Response
Personally Identifiable Information (PII).
Configuration Change for Accountability
Preventing users from clearing web browsing history.
Non-Repudiation Mechanism for Account Operation
A biometric authentication device that proves a person was genuinely operating an account.
Multifactor Authentication Scenario
A secured room requiring a user to swipe an ID badge and then type in a PIN code.
Personal Identification Number (PIN)
A "something you know" authentication factor because you must remember the digits.
Non-Repudiation Mechanism for Product Request
A token or receipt that proves a user requested a product and that it was delivered.
Administrator Account
An account that grants complete access to a computer.