Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

WIX3003 System Access

Total questions: 26

Worksheet time: 12mins

Name
Class
Date
1.

System access comprises the following functions

a)

Access Control

b)

Authorization

c)

Non-repudiation

d)

Authentication

2.

Checking the correct password corresponding to a given username to login is an example of

a)

Authentication

b)

Authorization

c)

Access Control

d)

Amputation

3.

Checking whether or not a given thumbprint corresponds to the information stored in the database is an example of

a)

Authentication

b)

Authorization

c)

Access Control

d)

Tokenisation

4.

Providing a user with access to the admin module is an example of

a)

Authentication

b)

Authorization

c)

Access Control

d)

Masking

5.

The entity responsible to set what a user can access is

a)

the authorization database

b)

the access control policy

c)

the security administrator

d)

NADMA

6.

Digital identity is not meant to be used when the user is engaged in an online transaction

a)

Correct

b)

Wrong

7.

According to NIST SP800-63, digital authentication establishes that a subject is who they claim to be

a)

Correct

b)

Wrong

8.

According to NIST SP800-63, digital identity is a unique representation of a subject engage in an online transaction

a)

Correct

b)

Wrong

9.

According to NIST SP800-63, the process of collecting our MyKad or passport to verify information about us, is an example of identity proofing

a)

Correct

b)

Wrong

10.

According to NIST SP800-63A, an applicant must be physically present in order for identity proofing to be performed

a)

True

b)

False

11.

According to NIST SP800-63A, identity proofing can be done remotely, i.e. without having the user to be physically present

a)

True

b)

False

12.

According to NIST SP800-63, when a user first register in the digital identity model, the user is called

a)

a Subscriber

b)

a Claimant

c)

an Applicant

d)

a Registrar

13.

Examples of a method of authentication involving something the user knows include

a)

smart card

b)

password

c)

staff badge

d)

PIN

14.

Examples of a method of authentication involving something the user has include

a)

thumb print

b)

RFID token

c)

passphrase

d)

student badge

15.

Authenticating using biometrics involves false positives. A false positive can mean

a)

a wrong user being given access

b)

a correct user being denied access

c)

a wrong user being denied access

d)

a correct user being given access

16.

Authenticating using biometrics involves false negatives. A false negative can mean

a)

a wrong user being given access

b)

a correct user being denied access

c)

a wrong user being denied access

d)

a correct user being given access

17.

Passwords can be stored in the clear as long as the salt is hidden

a)

True

b)

False

18.

The salt of a password can be stored in the clear

a)

True

b)

False

19.

In the same system, if two users use the same password and the salts given are also the same, then the hashed passwords are identical

a)

True

b)

False

20.

In the same system, if two users use the same password and the salts given are different, then the hashed passwords are different

a)

True

b)

False

21.

In access control, a PDF document is an example of an Object

a)

True

b)

False

22.

In access control, the ability to just read a particular PDF document is an example of an Access Right

a)

True

b)

False

23.

User A is the owner of file abc.docx and has read and write access. He then assigns another user, B to have read and write access. This scenario is an example of a

a)

discretionary access control (DAC)

b)

mandatory access control (MAC)

c)

role-based access control (RBAC)

d)

attribute-based access control (ABAC)

24.

Process A only has read access to file xyx.xlsx. The process cannot assign the same privilege to other processes. This scenario is an example of a

a)

message authentication code (MAC)

b)

role-based access control (RBAC)

c)

attribute-based access control (ABAC)

d)

mandatory access control (MAC)

25.

Which of the following are examples of consideration when granting access in Role-Based Access Control (RBAC)

a)

whether or not the user is a Technician

b)

whether or not the time of day is between 9am and 5pm

c)

whether or not the user is an Adminstrator

d)

whether or not the user holds a water jet

26.

Which of the following are valid examples of consideration when granting access to a door leading to a room in Attribute-Based Access Control (ABAC)

a)

whether or not the user has TOP SECRET level clearance

b)

whether or not the temperature of the room is between 10 and 15 degrees Celcius

c)

whether or not the day is a week day

d)

whether or not an ambulance is being blocked to allow others to pass