Domain 3 Flashcards

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Access Control?

A

The process of granting or denying specific requests to access information and information systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Authentication?

A

The process of verifying the identity of a user, system, or entity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Authorization?

A

The process of determining what resources a user or system is allowed to access after authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Accounting (or Auditing)?

A

The process of tracking user activities and system activities for security and compliance purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Identification?

A

The process where a user claims an identity, typically using a username or ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Multi-Factor Authentication (MFA)?

A

Authentication using two or more different types of factors: something you know, have, or are.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the three common authentication factors?

A

Something you know (password), something you have (token), something you are (biometrics).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Principle of Least Privilege?

A

A concept where users are granted only the access necessary to perform their job functions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Separation of Duties?

A

A security practice where critical tasks are divided among multiple individuals to prevent fraud or error.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Single Sign-On (SSO)?

A

An authentication process that allows a user to access multiple applications with one set of login credentials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is an Access Control List (ACL)?

A

A list that defines permissions attached to an object, specifying who can access it and what operations they can perform.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Role-Based Access Control (RBAC)?

A

Access control based on a user’s role within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Mandatory Access Control (MAC)?

A

An access control system where access is based on security labels and classifications, and decisions are enforced by the system, not the user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Discretionary Access Control (DAC)?

A

An access control model where the owner of the resource decides who has access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Attribute-Based Access Control (ABAC)?

A

An access control model that grants access based on attributes (characteristics) of the user, resource, and environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is a Biometric Authentication Factor?

A

An authentication method that uses unique physical characteristics, such as fingerprints or facial recognition.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is a Token in authentication?

A

A physical or digital object that provides access to systems, typically generating a time-based or random access code.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is Single-Factor Authentication?

A

Authentication that requires only one type of factor, such as a password.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is Time-Based One-Time Password (TOTP)?

A

A temporary, time-limited code used for authentication, typically generated by an app or device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is Access Provisioning?

A

The process of creating, modifying, disabling, and deleting user accounts and permissions.

22
Q

What is Account Management?

A

The management of user accounts throughout their lifecycle, ensuring appropriate access rights.

23
Q

What is Credential Management?

A

Processes and technologies used to issue, manage, and revoke credentials such as passwords or certificates.

24
Q

What is Privileged Account Management (PAM)?

A

Managing and monitoring accounts with elevated permissions to ensure security.

25
Q

What is Password Policy?

A

Rules that define how passwords must be created, used, and maintained to ensure strong security.

26
Q

What is a Security Token Service (STS)?

A

A service that issues security tokens for user authentication and authorization in federated systems.

27
Q

What is Context-Aware Access?

A

Access control decisions based on the context, such as location, device, or time of access.

28
Q

What is Federation in access control?

A

A process that allows users to access multiple systems across different organizations using a single identity.

29
Q

What is Identity Provider (IdP)?

A

A service that creates, maintains, and manages identity information and provides authentication services.

30
Q

What is Single Logout (SLO)?

A

A process where logging out of one application also logs you out of all linked applications.

31
Q

What is Principle of Need-to-Know?

A

Users should only have access to information necessary to perform their job duties.

32
Q

What is an Access Control Policy?

A

A document that defines how access to systems and data is managed and who is authorized.

33
Q

What is the main goal of access control?

A

To protect information and systems by ensuring only authorized individuals can access them.

34
Q

What is Identity and Access Management (IAM)?

A

The framework of policies and technologies to ensure the right individuals access the right resources at the right times.

35
Q

What is an example of something you have?

A

A smartcard or hardware security token.

36
Q

What is an example of something you know?

A

A password or PIN.

37
Q

What is an example of something you are?

A

A fingerprint or iris scan.

38
Q

What is the advantage of Single Sign-On (SSO)?

A

It reduces password fatigue and improves user convenience while maintaining security.

39
Q

What is an example of Role-Based Access Control (RBAC)?

A

A doctor automatically gaining access to patient records because of their job role.

40
Q

What distinguishes Mandatory Access Control (MAC) from Discretionary Access Control (DAC)?

A

MAC enforces policies at the system level; DAC allows owners to set permissions.

41
Q

What is an advantage of Attribute-Based Access Control (ABAC)?

A

More flexible and fine-grained access decisions based on user and environmental attributes.

42
Q

Why is Multi-Factor Authentication (MFA) stronger than Single-Factor Authentication?

A

It requires different types of credentials, making unauthorized access harder.

43
Q

Describe a possible risk of weak account management.

A

Former employees retaining access to systems and data after departure.

44
Q

What is an example of context-aware access control?

A

Allowing access only during business hours from corporate devices.

45
Q

What is an orphaned account?

A

An account that remains active after the employee has left the organization.

46
Q

What is access recertification?

A

A periodic review process to confirm that users have appropriate access rights.

47
Q

What is access revocation?

A

Removing a user’s access rights when they leave the organization or change roles.

48
Q

What is step-up authentication?

A

Prompting a user for additional authentication when performing high-risk actions.

49
Q

Why is it important to enforce strong password policies?

A

To make passwords harder to guess or crack, enhancing account security.

50
Q

What is Just-in-Time (JIT) Access?

A

Granting temporary, time-limited access to resources only when needed.

51
Q

How does privileged account management (PAM) reduce risk?

A

By tightly controlling and monitoring the use of administrative or elevated accounts.