Identity & Access Management Flashcards
What is CHAP for ?
Best solution against session hijacking.
What is OpenID good for ?
Includes Oauth and works with a REST api.
What is TPM ?
used for authentication, hardware based access control
How to handle many passwords ?
Implement a password manager.
What is CRL ?
Certification Revocation List
The 802.1x protocol handels …
… authentication at the switch.
What is NIPS ?
NIPS. (Network Intrusion Prevention System)
- Active / in band
- uses sensors
- Detection Methods
- behaviour/anomaly
- signature based
- rule based
- heuristic (combination of the above)
- cant read encrypted traffic!
Which is the most important in managing account permissions?
Account Recertification
Which Protocol mitigate easy network enumeration ?
LDAP, it is considered a directory or a phonebook of your network and if you make LDAP unavailable then the footprint of your network is not as easily obtained.
What is NIDS ?
NIPS. (Network Intrusion Prevention System)
- Passive / out of band
What is DEP refer to ?
DEP (Data Execution Prevention)
- used on WIN systems
What is a custodian security role ?
Human Resource Employee
What is an object in mandantory access control ?
Files
What is Type I in id management refers to ?
… something you know.
What is Type II in id management refers to ?
… something you have.