Chapter 4 Flashcards

1
Q

DAC

A

Discretionary access control:

Control access is defined based on the requestor identity and the access rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

MAC

A

Mandatory access control:

Control access is defined based on comparing the security labels with the security clearances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does RBAC relate to DAC and MAC?

A

Role based access control:

The control access is defined based on the roles of the user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Three classes of subject in an access control system

A

Owner
Group
World

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Subject vs object in access control

A

subject: an entity and it has the capability of accessing the objects
Object: an entity that contains the information and it is a resource for the access control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Access right?

A
Read
Write
Execute
Delete
Create
Search
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ACL vs capability ticket

A

An ACL is used to list the users and their permitted access rights
A capability ticket is used to specify the authorized objects and operations fora particular user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a protection domain?

A

an object which is having a set of objects together with access rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Four types of entities in a base model RBAC system.

A

User
Role
Permission
Session

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe three types of role hierarchy constraints.

A

Mutually exclusive roles
Cardinality
Prerequisite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

IN the NIST RBAC model, what is the difference between SSD and DSD?

A

Static separation of Duty relations:

Dynamic separation of duty relations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly