wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Managing User Security

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

The process of validating a user’s credentials is known as_____.

a)

authorization

b)

authenticiation

c)

verification

d)

compliance

2.

Which of the following is an example of multifactor authentication?

a)

A strong password and a security question

b)

Using fingerprints and an eye scan

c)

A digital token and password

d)

A digital token and a CAC

3.

Which of these is NOT an example of a biometric authentication method?

a)

A dongle

b)

Palm print

c)

Voice analysis

d)

Facial Recognition

4.

Which of the following describes a scenario in which an authorized user is denied access after using his or her fingerprint to gain access to a system?

a)

Cross-over error rate (CER)

b)

False rejection rate (FRR)

c)

False acceptance rate (FAR)

d)

True rejection rate (TRR)

5.

Often used in the military, this access level sets strict rules on data access.

a)

Discretionary Access Control

b)

Rule based Access Control

c)

Mandatory Access Control

d)

Role based Access Control

6.

The owner of the data assigns permissions in this access level control.

a)

Owner Based Access Control

b)

Role Based Access Control

c)

Mandatory Access Control

d)

Discretionary Access Control

7.

Which statement describes a characteristic of rule-based access control?

a)

It is the same as Mandatory Access Control.

b)

It can restrict the hours during which a user may log in.

c)

It assigns users to groups to ensure all users have the same rights.

d)

It has different permissions for each user.

8.

Which of the following is a justification for mandatory vacations?

a)

To ensure other people can perform a job duty

b)

To split up the duties of different individuals

c)

To evaluate and audit an employee’s data access

d)

To train others as network administrators

9.

Best practices include giving a user the minimum access to perform their job. This concept is known as ____.

a)

principle of permissions

b)

separation of privilege

c)

workstation privilege

d)

least privilege

10.

A database of network resources from Microsoft is called ____.

a)

Active Directory

b)

LDAP

c)

Microsoft IIS

d)

Kerberos

11.

When a user logs into the network, Kerberos issues ____ to gain access to resources.

a)

permissions

b)

rights

c)

tickets

d)

tokens

12.

The local database on a Windows workstation that contains user accounts is called?

a)

LDAP

b)

Security Account Manager

c)

A hash

d)

A Trust

13.

Objects that represent resources are called ____ in the Active Directory.

a)

resource objects

b)

organizational units

c)

domain objects

d)

leaf objects

14.

A set of rules that can automatically control access to resources is called a ____.

a)

right

b)

permission

c)

policy

d)

instruction

15.

Which of the following represents the most complex password for a user named Casey Wills?

a)

CaseyWiLLS

b)

hardtoguessp@ssword

c)

$trOnG

d)

PC@s3Y4EvR!

16.

Which is not a share permission?

a)

Read

b)

Write

c)

Change

d)

Full Control

17.

Jordan is given the read permission to Folder1. The group Engineers is given the full control permission to the Folder1 share. Jordan is a member of this group. What are her resulting share permissions to Folder1?

a)

Read

b)

Full control

c)

No permissions

d)

She has read permissions to her files only and full control to all other files.

18.

The net result of permissions a user has to a folder is called their ____ permissions.

a)

explicit

b)

inherited

c)

effective

d)

usable

19.

Which NTFS normal permission allows a user to delete files?

a)

Change

b)

Write

c)

Modify

d)

Delete

20.

The permissions a user is given at a specific location are called ____ permissions.

a)

Direct

b)

Implicit

c)

Express

d)

Explicit

21.

The ____ permission allows a user to take ownership of files and folders.

a)

modify

b)

full control

c)

advanced

d)

execute

22.

Olivia received permissions from a group called Engineers. Permissions she gets as a result of her group are called ____.

a)

Associated permissions

b)

Explicit permissions

c)

Implicit permissions

d)

Affiliated permissions

23.

How is the crossover error rate determined?

a)

The number of false rejections in a 24-hour time period

b)

The number of false acceptances in a 24-hour time period

c)

The point where false acceptances and false rejections meet

d)

The quality of the biometric equipment

24.

When a(n) ____ is configured, a user can be authenticated on one domain and automatically be authenticated on another.

a)

LDAP

b)

trust relationship

c)

SAML

d)

Kerberos security

25.

A user logs in with his or her username and password. Next, he or he is prompted to provide the correct answer to a security question. This scenario is an example of ____ authentication.

a)

multifactor

b)

Kerberos

c)

single-factor

d)

text-based

26.

Which password policy setting prevents a user from reusing an old password by checking a new password against previously used passwords?

a)

Minimum password age

b)

Maximum password age

c)

Account verification

d)

Enforce password history

27.

Which setting would be configured to determine how long an account will be disabled if a specific number of invalid attempts is made.

a)

Account lockout threshold

b)

Minimum lockout standard

c)

Account lockout duration

d)

Enforce account lockout

28.

Which of the following is true regarding a password that is used on a token or phone?

a)

It is considered a one-time password.

b)

It can be a significant security risk.

c)

It can be comprised only of numbers.

d)

It can be shared by multiple users.

29.

A user logs in with his or her username and password. Next, he or he is prompted to provide the correct answer to a security question. This scenario is an example of ____ authentication.

a)

multifactor

b)

Kerberos

c)

single-factor

d)

text-based

30.

Which is NOT true about the Active Directory?

a)

It is the security database used for local Windows computers.

b)

It is based off the LDAP standard.

c)

It has a hierarchical structure.

d)

User accounts contained in the directory are called objects.