AAA
What is the authorization concept known as implicit deny? A principle stating that access requires explicit authorization and everything else is rejected Which "something you have" authentication factor can be used to access high-risk applications? A hardware token What is rule-based access control? An authorization access model in which access is based on policies that are non-discretionary How does RSA's SecurID token provide multi-factor authentication? It generates a number code synchronized to a code on a server and is combined with a PIN. What is the purpose of authorization? To ensure that the person has the right to access a file or perform an action Where does tracking users' actions fit within the access control system? It is part of accounting and is required for non-repudiation. Which factor of authentication can be stolen and replayed from a remote location? A software token What service must be enabled for you to log on to multiple resources, servers, or sites using a common account and password? Single Sign On Which of the following describes Mandatory Access Control (MAC)? An authorization access model that has security clearance levels or compartments Which example uses single-factor authentication? A website requires a username, a password, and a PIN number. Which of the following is NOT used as a primary authentication factor? Somewhere you are A passphrase is a longer version of which factor of authentication? A password Which of the following is a common concern regarding the accuracy of biometrics? The false-negative and false-positive rate What is the authorization concept known as least privilege? A principle stating that a user should be granted rights necessary to perform a job and nothing more Which non-repudiation mechanism records who goes in or out of a particular area without user interaction? A video surveillance camera Which of the following describes Discretionary Access Control (DAC)? An authorization access model that stresses the importance of the owner who has full control over the resource What is Role-based Access Control (RBAC)? An authorization access model that groups users based on administrative or job functions Logging events in an audit log is what part of the access control system? Accounting Which non-repudiation mechanism can prove that the user was an author of a document? A physical or digital signature What is the set of rules that determines what actions you are allowed to perform on a computer and what resources you can access? Permissions What information can be used as a response to a security question? Personally Identifiable Information (PII) What configuration change can help collect tracking information for accountability purposes? Preventing users from clearing web browsing history Which non-repudiation mechanism can prove that a person was genuinely operating an account and that it was not hijacked? A biometric authentication device In which of the following scenarios is multifactor authentication being used? A secured room requires a user to swipe an ID badge and then type in a PIN code. A Personal Identification Number (PIN) is which type of authentication factor? "Something you know," because you must remember the digits Which non-repudiation mechanism proves that a user requested a product and that it was delivered? A token or receipt Which type of account would grant you complete access to a computer? Administrator