Domain 3 Flashcards

1
Q

Entity that requests access to assets.

Is a user, a process, a procedure, a
client (or a server), a program, or a
device.

Requests a service from an object.

A

Subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A device, process, person,
user, program, server, client, or other
entity that responds to a request for
service.

Anything that provides service to a user.

A building, a computer, a file, a
database, a printer or scanner

A

Object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

To allow or deny access to an object by comparing the validated identity of the subject to an access control list.

Allow access to an object.

How much access is allowed.

A

Rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

An information security strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.

A

Defense in depth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Each user is granted access to only the items they need and nothing further.

A

Least Privilege

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Granted to a person, subject or group but not to others.

To create, read, update and delete.

A

Privileged Access Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Beyond normal users like managers and administrators.

To have greater control over data and applications.

A

Privileged Accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly