1/13
Vocabulary flashcards covering access control models, authentication factors, network protocol port numbers, IAM functions, Active Directory components, and SSO authentication flow from Chapter 4.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Access Control Models
Models used to manage access to resources, which include RBAC, MAC, DAC, and ABAC.
Authentication Factors
Categories of identity verification, consisting of 'Something you know', 'Something you are', and 'Something you have'.
Biometric Metrics
Performance metrics for biometric systems, including CER (Crossover Error Rate), FRR (False Rejection Rate), and FAR (False Acceptance Rate).
IAM System Main Functions
The 4 primary functions of an Identity and Access Management system: 1. Identity, 2. Authentication, 3. Authorization, and 4. Accounting.
RADIUS
Remote Authentication Dial In User Service; an open-source protocol that runs on ports 1812 and 1813.
TACACS+
A protocol proprietary to Cisco running on port 49, used for remote device management.
Active Directory Components
Key structural elements of Active Directory, which include Organizational Unit, Tree, Forrest, Domain, and Object.
Linux User Management Commands
Commands used in Linux to manage users and groups: Useradd, Userdel, Usermod, Passwd, and Groups.
LDAP / LDAPS Ports
LDAP operates on port 389, while secure LDAPS operates on port 636.
Web and Secure Shell Ports (HTTP, HTTPS, SSH)
HTTP operates on port 80, HTTPS operates on port 443, and SSH operates on port 22.
FTP Port
File Transfer Protocol operates on port 21.
Security Management Policies
Administrative access controls designed to minimize risk, including Least Privilege, Separation of Duties, Job Rotation, and Mandatory Vacation.
Implicit vs Explicit Deny
Implicit Deny blocks access by default if not expressly allowed, whereas Explicit Deny specifically designates access to be denied.

SSO Authentication Flow Diagram
Diagram illustrating a Logon Request sent from a Principal to the KDC (Authentication Service), which issues a Ticket Granting Ticket to access an Application Server.