Identity & Access Management Flashcards

1
Q

What is CHAP for ?

A

Best solution against session hijacking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is OpenID good for ?

A

Includes Oauth and works with a REST api.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is TPM ?

A

used for authentication, hardware based access control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How to handle many passwords ?

A

Implement a password manager.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is CRL ?

A

Certification Revocation List

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The 802.1x protocol handels …

A

… authentication at the switch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is NIPS ?

A

NIPS. (Network Intrusion Prevention System)

  • Active / in band
  • uses sensors
  • Detection Methods
    • behaviour/anomaly
    • signature based
    • rule based
    • heuristic (combination of the above)
  • cant read encrypted traffic!
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which is the most important in managing account permissions?

A

Account Recertification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Protocol mitigate easy network enumeration ?

A

LDAP, it is considered a directory or a phonebook of your network and if you make LDAP unavailable then the footprint of your network is not as easily obtained.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is NIDS ?

A

NIPS. (Network Intrusion Prevention System)

- Passive / out of band

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is DEP refer to ?

A

DEP (Data Execution Prevention)

- used on WIN systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a custodian security role ?

A

Human Resource Employee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is an object in mandantory access control ?

A

Files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Type I in id management refers to ?

A

… something you know.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Type II in id management refers to ?

A

… something you have.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Type III in id management refers to ?

A

… something you are.