chaps 5-10 study for final Flashcards

1
Q

what is AAA?

A

AAA= Authentication, Authorization, Aditing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is RBAC?

A

RBAC= role based access control: each role such as managers, employees etc. get parameters for access instead of using a user-access control method. -easier to cover more people.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Mandatory access control?

A

no ability to change rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Discretionary Access Control

A

departments are allowed to alter rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

are automated password resets good and are they safe? y or y not?

A

no not safe, can social engineer for authentication information then pretend to be real employee to reset pword for personal gain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

TGT

A

Ticket granting Ticket: similar to a wrist band, allows communication to continue without re-authenticating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

directory servers do what?

A

store info for security and employee contacts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

LDAP?

A

Lightweight Directory Access Protocol: governs communication between directory servers and devices, including authentication servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AD?

A

microsoft organized directories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

domain controller used or what?

A

controls the resources in a domain and is used allong with an AD active directory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what is trust when it comes to directory servers?

A

bi-directional (mutual)
-one way
Transitive: can trust others by learning from trusted servers.
Intransive: will not trust others, even when learned from trusted servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is a metadirectory server?

A

connects several directory servers together.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

how does one in security think about trust?

A

not as how much to trust but instead in terms of risk reduction or levels of risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In CobiT, entry must be ________.

justified
logged
Both justified and logged
Neither justified nor logged

A

Both justified and logged

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The book recommends that passwords be at least ________ characters long.

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Compared to access control based on individual accounts, RBAC is ________.
less prone to error
more expensive
Both less prone to error and more expensive
Neither less prone to error nor more expensive

A

less prone to error

17
Q
Which of the following is one of the four bases for authentication credentials?
Both What you know and What you have
Neither What you know nor What you have
What you know
What you have
A

Both What you know and What you have

18
Q

A ________ card stores authentication data.

magnetic stripe
smart
Both magnetic stripe and smart
Neither magnetic stripe nor smart

A

Both magnetic stripe and smart

19
Q

if a provable attack packet is detected by firewall what happens?

A

it gets dropped.. drops packet

20
Q

what is ingress filtering?

A

firewall examines packets entering the network from the outside.

21
Q

what is egress filtering?

A

firewall scans ip packets that are leaving the network.

22
Q

if a firewall becomes overloaded with traffic what does it do with packets?

A

drops packets it can not process.