501 Chapter 2 Flashcards
____ proves identity with some type of credentials
Authentication
AAA stands for
Authentication, Authorization, Accounting
____ work together with AAA to provide CAMS
Identification
CAMS stand for
Comprehensive Access Management System
List five (5) authentication factors
Something you know, Something you are, Somewhere you are, Something you do, Something you have
least secure of all authentication factors
Something you know
credit card-sized embedded with microchip and certificate
smart card
PKI stands for
Public Key Infrastructure
____ holds a user’s private key
Embedded Certificate
____ is a specialized type of smartcard used by the US Department of Defense
CAC
CAC stands for
Common Access Card
____ is a specialized type of smartcard used by the US Federal agencies
PIV
PIV stands for
Personal Identification Verification
sometimes called hardware tokens to differentiate them from logical or software tokens
fob
includes LCD display that changes periodically every 60 secs
fob
HMAC stands for
Hash-based Message Authentication Code
____ is an open standard used for creating one-time passwords similar to those used in tokens and fobs
HOTP
HOTP stands for
HMAC-based One-Time Password
____ is similar to HOTP but it uses a timestamp instead of a counter
TOTP
TOTP stands for
Time-based One-Time Password
____ is a network authentication mechanism used within Windows Active Directory domains and some Unix environments known as realms
Kerberos
three (3) factors for Kerberos to work
A method of issuing tickets, time synchronization, a database of subject or users
KDC stands for
Key Distribution Center
____ uses a complex process of issuing ticket-granting tickets (TGTs) and other tickets
KDC
requires all systems to be synchronized and within 5 minutes of each other
time synchronization
a suite of protocols provides authentication, integrity, confidentiality @Windows system,
uses a Message Digest hashing algorithm to challenge users and check their credentials
NTLM
list the three versions of NTLM
NTLM
NTLMv2
NTLM2
NTLM stands for
New Technology LAN Manager
a simple MD4 hash of the user’s password
NTLM
____ has been cracked and therefore NTLM is not recommended for use
MD4
challenge-response authentication protocol,
creates HMAC-MD5 hash composed of a combination of username, logon domain name, user password, current time and more
NTLMv2
NTLMv2 + mutual authentication,
the client authenticates with server as well as server authenticates with the client
NTLM2