NEW
Font size
WorksheetsIdentity and Access Management
Total questions: 13
Worksheet time: 1hrs 5mins
Your organization is planning to implement remote access capabilities. Management wants strong authentication and wants to ensure passwords expire after a predefined time interval. Which of the following best meets this need?
HOTP
TOTP
CAC
Kerberos
Your organization has decided to implement a biometric solution for authentication. One of the goals is to ensure that the system is highly accurate. Which of the following provides the BEST indication of accuracy with the biometric system?
The lowest possible FRR
The highest possible FAR
The lowest possible CER
The highest possible CER
Employees enter a username and password into the company application from their smartphone and the application logs their location using GPS. Which type of authentication is being used?
One-factor
Dual-factor
Something you are
Somewhere you are
A network includes a ticket-granting ticket server used for authentication. Which authentication service does this network use?
Shibboleth
SAML
LDAP
Kerberos
Lisa is a training instructor and she maintains a training lab with 18 computers. She has enough rights and permission so that she can configure them as needed for classes. However, she does not have the rights to add them to the organizations domain. What is being shown in this example?
Least privilege
Need to know
Group-based privileges
Location-based policies
Marge is reviewing an organizations account management processes. She wants to ensure that security log entries accurately report the identity of personnel taking specific actions. Which step would best meet this requirement?
Update ACLs for all files and folders
Implement role-based privileges
Use an SSO solution
Remove all Shared accounts
A recent security audit discovered several apparently dormant user accounts. Although users could log on to the accounts, no one had logged on to them for more than 60 days. You later discovered that these accounts are for contractors who work approximately one week every quarter. Which of the following is the BEST response to this situation?
Remove the account expiration from the accounts.
Delete the accoutns.
Reset the accounts.
Disable the accounts.
A recent security audit discovered several apparently dormant user accounts. Although users could log on to the accounts, no one had logged on to them for more than 60 days. You later discovered that these accounts are for contractors who work approximately one week every quarter. Which of the following is the BEST response to this situation?
Remove the account expiration from the accounts.
Delete the accoutns.
Reset the accounts.
Disable the accounts.
Members of a project team chose to meet at a local library to complete some work on a key project. All of them are authorized to work from home using a VPN connection and have connected from home successfully. However, they found that they were unable to connect to the network using the VPN from the library and they could not access any of the project data. Which of the following choices is the MOST likely reason why they can't access this data?
Role-based access control
Time-of-day access control
Location-based policy
Discretionary access control
You need to create an account for a contractor who will be working at your company for 60 days. Which of the following is the BEST security step to take when creating this account?
Configure history on the account.
Configure a password expiration date on the account.
configure and expiration date on the account .
Configure complexity.
A company recently hired you as a security administrator. You notice that some former accounts used by temporary employees are currently enabled. Which of the following choices is BEST response?
Disable all the temporary accounts.
Disable the temporary accounts you've noticed are enabled.
Craft a script to identify inactive accounts based on the last time they logged on.
Set account expiration dates for all accounts when creating them.
Developers are planning to develop an application using role-based access control. Which of the following would they MOST likely include in their planning?
A listing of labels reflecting classification levels
Arequirements list identifying need to know
A listing of owners.
A matrix of functions matched with their required privileges.
Your organization is implementing a SDN. Management wants to use an access control model that controls access based on attributes. Which of the following is the BEST solution?
DAC
MAC
Role-BAC
ABAC
