Random CISSP Flashcards
Sniffing attack
A sniffing attack uses a sniffer (also called a packet analyzer or protocol analyzer) to capture data and can be used to read passwords sent across a network in cleartext.
A side-channel attack
is a passive, noninvasive attack used against smart cards. Methods include power monitoring, timing, and fault analysis attacks.
role-based access control
A role-based access control policy grants specific privileges based on roles, and roles are frequently job based or task based.
Discretionary access controls
Discretionary access controls allow owners of information to control privileges
mandatory access controls
mandatory access controls use labels to control privileges
Clipping levels
Clipping is a form of nonstatistical sampling that reduces the amount of logged data based on a clipping-level threshold.
Log analysis reviews
Log analysis reviews log information looking for trends, patterns, and abnormal or unauthorized events.
Audit trails are considered to be what type of security control
Passive detective
Audit trails
Audit trails are a passive form of detective security control.
Synchronous token
A synchronous token generates one-time passwords and displays them in an LCD, and this password is synchronized with an authentication server.
asynchronous token
An asynchronous token uses a challenge-response process to generate the token.
Type 1 biometric error
A Type 1 error occurs when a valid subject is not authenticated and is also known as a false negative authentication.
Type 2 biometric error
A Type 2 error occurs when an invalid subject is authenticated. This is also known as a false positive authentication.
crossover error rate
The crossover error rate (also called equal error rate) compares the rate of Type 1 errors to Type 2 errors and provides a measurement of the accuracy of the biometric system.
What is the best choice to support federated identity management systems?
Service Provisioning Markup Language (SPML)