IAAA Flashcards

1
Q

identification

A

identify an entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

is identification and authentication the same

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is authentication

A

proof who you claim to be

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

way of authentication

A

password, PIN, Biometric

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what is no repudiation

A

prevent someone from denying the authenticity of a statement or their actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

authorization

A

level of clearance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are clearances

A

the type of data, system, application you have access to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

accountability

A

holding user responsible for their action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what’s account audit

A

to make sure that privileges are appropriately assigned and updated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

provisioning (Identity lifecycle)

A

create new account n assign privileges ( Authorization)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

review (identity lifecycle)

A
  1. periodic account review
  2. disable inactive account
  3. audit privilege creep
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is privilege creep

A

when someone accumulates privileges over time as their roles change, but older privileges are not relinquished

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

revocation (identity lifecycle)

A

disable account of employee who leave, retired, or are terminated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Authentication factor
type 1

A

something that you know:
.password
.pin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

authentication factors
type 2

A

something that you have
-smart card
-mobile SIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

authentication factors
type 3

A

something that you are
-retina pattern
-finger prints

17
Q

what’s MFA

A

MFA stands for multifactor Authentication. it’s combine two or more types to strengthen the authentication process

18
Q

roles of accountability

A

audit of logs and account to identify any violations

19
Q

authorization min

A

give a subject the minimum data/ info and privilege that he/she needs to complete their job.
it’s the fundamental idea in cybersecurity to provide least privileges

20
Q

why is minimum privileges important?

A

if privileges is unchecked, they can cause serious cybersecurity repercussions. they can be abused

21
Q

how is accountability enforced

A

log audits, account audits, job rotations, and non-repudiation