Chpt 13 Flashcards

1
Q

Define asset

A

Information, systems, devices, facilities and personnel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the three primary control types?

A

Preventive
Detective
Corrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the four other Access Control types?

A

Deterrent
Recovery
Directive
Compensation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are cognitive passwords?

A

A series of challenge questions about facts or predefined responses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a type 1 error?

A

FRR - False Rejection Rate

When a valid subject is not authenticated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a type 2 error?

A

FAR - False Acceptance Rate.

When an invalid subject is authenticated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the three stages of the Identity and Access Lifecycle?

A

Provisioning
Account review
Account revocation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Describe a subject

A

The subject is always the entity that receives information or data from an object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the primary purpose of Kerberos?

A

Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the best choice to support a federated Identity Management system?

A

SAML - Security Assertion Markup Language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What acts as the client in RADIUS architecture?

A

The network access server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly