wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CISSP CH5 Identity and Access Management

Total questions: 28

Worksheet time: 2hrs 28mins

Name
Class
Date
1.

The required access level which allows the user to change the content of backup script

a)

Read Only

b)

Read and Write

c)

Execute

d)

Read and Execute

2.

To mitigate tailgating . what should be considered ?

a)

People Awareness

b)

Implement double doors

c)

Implement Anti-PassBack feature

d)

All above

3.

To open a highly secured safe inside a financial institute, the BEST way to grant access is to use

a)

Bio-metric access controls

b)

Personal Identification Number access control

c)

Digital Certificates access controls

d)

Dual Custody access control

4.

Which of the following the is BEST identity verification method to access your desktop

a)

Password

b)

Finger Print

c)

PIN and Smart card

d)

Retina scan

5.

In Kerberos, the ticket granting ticket is initially provided by

a)

User

b)

Authentication server

c)

Ticket Granting Service

d)

Target

6.

In disaster recovery plan, it was noted the SSO service is located in one Data center. What will be your recommendation as security professional ?

a)

Implement load balancing technique with another SSO server in the same data center

b)

Implement Redundant Array of Independent Disk for the mentioned server

c)

Implement Fail over in a different Geo-location

d)

Implement full daily backup

7.

From the administrative point of view what is biggest concern regarding Bio metric Physical access control

a)

Type 1 errors

b)

Type 2 errors

c)

Cross Error Rate

d)

user errors

8.

In DAC the access granted by

a)

System Admin

b)

User

c)

Data Owner

d)

All of the above

9.

In very high sensitive facility, data access controls follows

a)

DAC model

b)

MAC model

c)

RBAC

d)

RuBAC

10.

Which of the following supports Audit clauses

a)

Identity management

b)

Authentication

c)

Authorization

d)

Accounting

11.

You are a security professional who is investigating a security incident of non-authorized access, your BIGGEST concern is

a)

Access logs contained plain text usernames

b)

Access logs time format

c)

Integrity of access logs

d)

Access logs retention policy

12.

One way to avoid emanation from your data center is to

a)

Implement Magnetic field around the facility

b)

Zone control review

c)

Install High gain antennas

d)

Install fences around the facility

13.

RFID's are susceptible to

a)

Spoofing attacks

b)

Denial of Services attacks

c)

Traffic Analysis attacks

d)

All above

14.

RFID are ________________ devices

a)

active

b)

passive

c)

fail over

d)

active-passive

15.

When the false rejections rate equals false acceptance rate , the it is called

a)

Type I errors

b)

Type II errors

c)

Type III errors

d)

Cross Rate Error

16.

In MAC system model, _____________ makes decision based on ____________

a)

System , owner discretion

b)

Owner, Labels

c)

System , Labels

d)

Owner , owner discretion

17.

Role based Access controls, which statement is correct

a)

Users are mapped to access rights then access rights are mapped to roles

b)

Roles represent users and access rights

c)

User are mapped to roles then roles are mapped to access rights

d)

users are mapped to access rights directly

18.

Which one of the following will be the best secured Identification key for John Bob as a new webmaster of company ABC ?

a)

john.bob@abc.com

b)

webmaster@abc.com

c)

john.bob

d)

bj230579

19.

When an employee of company A is required to authenticated to check his medical claims at the company B using his company A credentials. This feature called _________

a)

Single Sign On

b)

Script Based Sign On

c)

Cross Domain Single Sign On

d)

Multi factor authentication

20.

To avoid Privilege Creep problem, you should not apply the following EXCEPT

a)

Apply MAC

b)

Apply DAC

c)

Apply RBAC

d)

Apply RuBAC

21.

The BIGGEST concern of using Kerberos is

a)

using symmetric key encryption

b)

sending passwords over the wire

c)

single point of failure

d)

server stores password in clear text

22.

In Kerberos the service requester presents _______ to the service provider server

a)

username and password

b)

encrypted password

c)

Authenticated token

d)

Ticket granting ticket

23.

The Ticket Granting Ticket is granted by

a)

Client

b)

Ticket Granting Service (TGS)

c)

Authenticating Service (AS)

d)

Service Server Provider

24.

The ultimate goal of data classification is

a)

Determine the sensitivity

b)

Apply proper security controls

c)

Determine the criticality

d)

Integrate with security policy

25.

Data classification is the done by

a)

Senior Management

b)

Security Professional

c)

Data Owner

d)

Data Custodians

26.

To check completeness, correctness, and compliance of a data set is known by

a)

Validation

b)

Verification

c)

Quality Assurance

d)

Quality Control

27.

A user opened the shared folder and opened a document in the word processor, but he got an error when he tried to print it. This an example of

a)

Identity access problem

b)

Authentication access problem

c)

Authorization access problem

d)

Accounting problem

28.

To ensure, protection of users' identities, least privilege concept in place, tracking users' activities, and validation of their identities. You need should NOT implement EXCEPT ......

a)

Identification, Authentication , Authorization, Encryption

b)

Identification, Authentication , Authorization, Hashing

c)

Identification, Authentication , Authorization, Accountability

d)

Identification, Authentication , Authorization, non-repudiation