Chapter 13 Flashcards

1
Q

Biometric authentication:

Type I error - False negative
Type II error - False positive

A

CER: FRR = FAR
Low CER - more accurate

Enrollment - create reference profile; 2 mins acceptable
Throughput - authentication time; 6 secs acceptable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cognitive password

A

Security question

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Authentication Factors

A

Type 1 - something you know
Type 2 - something you have
Type 3 - something you are

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Authoritative Password Recommendations

A

NIST:
1. Must be hashed
2. Should not expire
3. Can be copied/paste
4. Should not require special chars
5. Should be able to use all chars
6. Should be 8 - 64 chars
7. Use screen passwords

PCI DSS:
1. Expire every 90 days
2. At least 12 chars
3. Both numeric and alpha
4. Pwd history of 4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Device authenticator (Token)

A

Time-based OTP (Sync)
Hash-based OTP (Async)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Device authentication

A
  • matched registered attributes of device (fingerprinting)
  • context-aware authentication; place, time of day, etc.
  • use 802.1X
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SSO

A

Authenticate once to access multiple resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Federated Identity Mgmt (FIM)

A
  • SSO for multiple orgs
  • Via SAML, OpenID, OAuth, OpenID Connect
  1. Cloud-based federation - user 3rd party service for fed identity sharing
  2. On-premise
  3. Hybrid - cloud and on-prem
  4. Just-in-time - only create on first access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Credential Manager API

A

e.g. login to Facebook from Google

How well did you know this?
1
Not at all
2
3
4
5
Perfectly