Domain 3 Flashcards
Access Control Concepts
Which of the following is an example of security control?
Firewall
Subject definition
any entity that requests
access to asset. May be a user, program, etc., is active in initiating the request for services, and should have some level of clearance
Object definition
an entity that responds to a request for service. May be a building, file, etc., provides service to a user, is passive in the request, do not have their own access control logic, and may have a classification
Rules definition
an instruction developed to
allow or deny access to an object by comparing the validated identity
of the subject to an
access control list
What is the definition of an object in the context of access controls?
An entity that responds to a request for service
Derrick logs on to a system to read a file.
In this example, Derrick is the ______.
Subject
Which of the following is a subject?
User
What is the strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of an organization?
Layered Defense
How does privileged access management implement the principle of least privilege?
By granting each user access only to the items they need
Physical access controls are
tangible methods or mechanisms that
limit someone from getting access to an
area or asset
Logical access controls are
electronic methods that limit someone
from getting access to systems, and
sometimes even to tangible assets or areas, including passwords, biometrics, etc.
Which of the following is an example of a logical access control method?
Biometrics on a smartphone
Limiting access to data on the network would be considered which of the following controls?
Logical or technical controls
A control serves to
reduce the risk
according to where it falls within
the risk tolerance of the individual
or organization
What would be considered an administrative control in the context of seat belt usage?
Passing a law requiring seat belt use