Chpt 13 Flashcards
Define asset
Information, systems, devices, facilities and personnel.
What are the three primary control types?
Preventive
Detective
Corrective
What are the four other Access Control types?
Deterrent
Recovery
Directive
Compensation
What are cognitive passwords?
A series of challenge questions about facts or predefined responses.
What is a type 1 error?
FRR - False Rejection Rate
When a valid subject is not authenticated.
What is a type 2 error?
FAR - False Acceptance Rate.
When an invalid subject is authenticated
What are the three stages of the Identity and Access Lifecycle?
Provisioning
Account review
Account revocation
Describe a subject
The subject is always the entity that receives information or data from an object
What is the primary purpose of Kerberos?
Authentication
What is the best choice to support a federated Identity Management system?
SAML - Security Assertion Markup Language
What acts as the client in RADIUS architecture?
The network access server.