Week 1 Modules 1&2 Flashcards

Intro concepts and terms, Actors and Processes

1
Q

The process of establishing the identities of interacting parties in an electronic transaction with a certain level of confidence

A

Identity Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are 3 reasons to having identity management?

A

Logical Access Control
Monitoring
Physical Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an entity?

A

Something with a separate and distinct existence that can be identified in context

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
The following are examples of what?
Human, agency, object, users, devices
A. Attribute
B. Entity
C. Actor
D. None of the above
A

B. Entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A characteristic or property of an entity. Describes an aspect of an entity.

A

Attribute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The following are examples of what?

SSN, VIN #, IPAddress, Make of a car

A

Attribute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An attribute or set of attributes that uniquely identifies a subject (entity) within a domain or context.

A

Identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Environment where an entity uses a set of attributes for identification, and other purposes.
OR
Environment with defined boundary conditions in which entities exist and interact.

A

Domain/Context

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a digital representation of information known about a specific individual, group or organization.

A

Digital Identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is identity information that unambiguously distinguishes one entity from another in a given domain?

A

Identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

________ is the process of recognizing an entity as distinct from other entities in a domain.

A

Identification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

_______ applies verification to claimed or observed attributes.

A

Identity Verification (Authentication)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Evidence, during authentication, is called an ______

A

Authenticator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The structure linking the identity and authenticator is called a ______.

A

Credential

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The validity of a credential involves verifying what?

A. Correctness
B. Integrity
C. Authenticity
D. Currency
E. Attributes
F. All of the above
A

A. Correctness
B. Integrity
C. Authenticity
D. Currency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does Authenticity mean?

A

issued by the correct authority

17
Q

What is correctness?

A

conformance to the rules pertaining to the type of credential

18
Q

______ is a subject whose identity is to be verified using one or more authentication protocols.

A

Claimant

19
Q

A _____ is an entity that checks a claimant’s identity by verifying the claimant’s possession and control of one or two authenticators, using an authentication protocol.

A

Verifier

20
Q

A category describing the strength of the authentication process.
A. Identity Access Assurance Level (IAAL)
B. Authentication Strength Level (ASL)
C. Authenticator Assurance Level (AAL)
D. None of the above

A

C. Authenticator Assurance Level

21
Q

________ is a defined sequence of messages that demonstrates the claimant has possession and control of a valid authenticators to establish their identity. Can demonstrates the claimant is communicating with the intended verifier.

A

Authentication protocol

22
Q

What is an Identity Media (Token)?

A

A device or object storing one or more credentials, claims, or attributes related to a single entity.

23
Q

The ________ is an entity that creates, assigns, maintains and issues identity and credentials. Can also be a verifier.

A

Identity Provider/Identity Information Provider (IdP)

24
Q

What is an identity assertion?

A

Statement made by an identity provider, used by a relying party for providing a service.
Proof of a successful authentication

25
Q

What is the level of assurance in the result of an identity verification/authentication?

A

Identity (authentication) assurance

26
Q

A _____ is authorized to enroll in an identity system and is authenticated for eligibility to access resources or services.

A. User
B. Subject
C. Principal
D. Actor

A

C. Principal

27
Q

The below are responsibilities of who?

  1. Provide accurate identity information for enrollment
  2. request to be identified and authorized for access
  3. access to own information and request modification if needed
A

Principal

28
Q

The ____ performs identity verification or authentication.

A. Verifier
B. Authorizer
C. Enroller
D. None of the above

A

A. Verifier

29
Q

An entity that receives identity assertions from a verifier and relies on them for a purpose is the _____.

A

Relying party (RP)

30
Q
What are the phases of the Identity Management Lifecycle? (choose all)
A. Enrollment
B. Planning
C. Credential Management
D. Authentication
E. Monitoring
A

A. Enrollment
C. Credential Management
D. Authentication

31
Q

____ and _____ are the processes involved in the Enrollment Phase.

A

Identity proofing

Registration

32
Q

The Lifecycle management phase ____ is the collection of processes involved in making an entity known within a domain/context.

A

Enrollment

33
Q

______ is a form of authentication based on identity evidence that is performed as the condition for enrollment.
Could be a Birth Certificate, ID, Passport.

A

Identity Proofing

34
Q
The process of recording an entity's identity information in an identity register.
A. Enrollment
B. Registration
C. Recording
D. Identifier
A

B. Registration

35
Q

Processes in the ______ phase in the Lifecycle Management that enable an entity to join, participate in and terminate participation in a domain/context.

A

Credential Management

36
Q
The activities included in the Credential Management Phase of the Lifecycle include:
A. Issue
B. Bind
C. Verify
D. Revoke
E. Modify
F. Record-keeping
A

A. Issue
B. Bind
D. Revoke
F. Record-keeping

37
Q

According to ISO/IEC, the following are part of what phase in the Management Lifecycle?
Credential Creation, Issuance, Activation, Storage, Suspension, Revocation, Destruction, Renewel, Record-Keeping

A

Credential Management Phase

38
Q

The _____ phase of the Management Lifecycle includes the use of a protocol to demonstrate possession of a credential to establish confidence in a claim of identity.

A

Authentication (usage)