NEW
Font size
WorksheetsCISSP CH5 Identity and Access Management
Total questions: 28
Worksheet time: 2hrs 28mins
The required access level which allows the user to change the content of backup script
Read Only
Read and Write
Execute
Read and Execute
To mitigate tailgating . what should be considered ?
People Awareness
Implement double doors
Implement Anti-PassBack feature
All above
To open a highly secured safe inside a financial institute, the BEST way to grant access is to use
Bio-metric access controls
Personal Identification Number access control
Digital Certificates access controls
Dual Custody access control
Which of the following the is BEST identity verification method to access your desktop
Password
Finger Print
PIN and Smart card
Retina scan
In Kerberos, the ticket granting ticket is initially provided by
User
Authentication server
Ticket Granting Service
Target
In disaster recovery plan, it was noted the SSO service is located in one Data center. What will be your recommendation as security professional ?
Implement load balancing technique with another SSO server in the same data center
Implement Redundant Array of Independent Disk for the mentioned server
Implement Fail over in a different Geo-location
Implement full daily backup
From the administrative point of view what is biggest concern regarding Bio metric Physical access control
Type 1 errors
Type 2 errors
Cross Error Rate
user errors
In DAC the access granted by
System Admin
User
Data Owner
All of the above
In very high sensitive facility, data access controls follows
DAC model
MAC model
RBAC
RuBAC
Which of the following supports Audit clauses
Identity management
Authentication
Authorization
Accounting
You are a security professional who is investigating a security incident of non-authorized access, your BIGGEST concern is
Access logs contained plain text usernames
Access logs time format
Integrity of access logs
Access logs retention policy
One way to avoid emanation from your data center is to
Implement Magnetic field around the facility
Zone control review
Install High gain antennas
Install fences around the facility
RFID's are susceptible to
Spoofing attacks
Denial of Services attacks
Traffic Analysis attacks
All above
RFID are ________________ devices
active
passive
fail over
active-passive
When the false rejections rate equals false acceptance rate , the it is called
Type I errors
Type II errors
Type III errors
Cross Rate Error
In MAC system model, _____________ makes decision based on ____________
System , owner discretion
Owner, Labels
System , Labels
Owner , owner discretion
Role based Access controls, which statement is correct
Users are mapped to access rights then access rights are mapped to roles
Roles represent users and access rights
User are mapped to roles then roles are mapped to access rights
users are mapped to access rights directly
Which one of the following will be the best secured Identification key for John Bob as a new webmaster of company ABC ?
john.bob@abc.com
webmaster@abc.com
john.bob
bj230579
When an employee of company A is required to authenticated to check his medical claims at the company B using his company A credentials. This feature called _________
Single Sign On
Script Based Sign On
Cross Domain Single Sign On
Multi factor authentication
To avoid Privilege Creep problem, you should not apply the following EXCEPT
Apply MAC
Apply DAC
Apply RBAC
Apply RuBAC
The BIGGEST concern of using Kerberos is
using symmetric key encryption
sending passwords over the wire
single point of failure
server stores password in clear text
In Kerberos the service requester presents _______ to the service provider server
username and password
encrypted password
Authenticated token
Ticket granting ticket
The Ticket Granting Ticket is granted by
Client
Ticket Granting Service (TGS)
Authenticating Service (AS)
Service Server Provider
The ultimate goal of data classification is
Determine the sensitivity
Apply proper security controls
Determine the criticality
Integrate with security policy
Data classification is the done by
Senior Management
Security Professional
Data Owner
Data Custodians
To check completeness, correctness, and compliance of a data set is known by
Validation
Verification
Quality Assurance
Quality Control
A user opened the shared folder and opened a document in the word processor, but he got an error when he tried to print it. This an example of
Identity access problem
Authentication access problem
Authorization access problem
Accounting problem
To ensure, protection of users' identities, least privilege concept in place, tracking users' activities, and validation of their identities. You need should NOT implement EXCEPT ......
Identification, Authentication , Authorization, Encryption
Identification, Authentication , Authorization, Hashing
Identification, Authentication , Authorization, Accountability
Identification, Authentication , Authorization, non-repudiation
