Security Controls Flashcards
what is the difference between auditing and monitoring?
auditing is one time whereas monitoring is an ongoing process
is a penetration test an audit or monitoring?
an audit
whats a kensington lock?
a cable that uses a tie to secure smaller devices
what is DAC?
Discretionary Access Control
how is DAC utilized?
access control method where access is determined by the owner of the resource.
what is MAC?
Mandatory Access Control
how is MAC (Message Authentication Code) utilized?
access control policy where the computer system decides who gets access.
what is RBAC?
Role Based Access Control
how is RBAC(Role Based Access Control) utilized?
access model that is controlled by the system that focuses on a set of permissions versus an individuals permissions.
what is Zero Trust?
security framework that requires the users to be authenticated, authorized and validated
what is identification?
provides identity
what is authentication?
validates identity
what is a TOTP?
time based one time password
what does a TOTP(Time Based One Time Password) do?
computes password from a shared secret and the current time.
what is HOTP?
HMAC Based One Time Password