Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 14 Controlling and Monitoring Access

Total questions: 10

Worksheet time: 6mins

Name
Class
Date
1.

Which of the following principles ensures that subjects receive only the privileges necessary to perform their job duties?

a)

Need to know

b)

Least privileges

c)

Separation of Duties and Responsibilities

d)

Context-dependent control

2.

What is one of the 9 safety precautions?

a)

Buy an expensive cybersecurity service

b)

Educate users about security

c)

Have a shared password file.

d)

Change the password every day!

3.

Is it important to encrypt sensitive data in transit, including passwords sent over a network?

a)

True

b)

False

4.

What are the key tasks that security professionals complete early in a risk management process?

a)

Identifying assets

b)

Identifying threats

c)

Identifying vulnerabilities

d)

Identifying potential losses

e)

Identifying users

5.

Which correspond to approaches to identify threats?

a)

Focused on Software

b)

Focused on Programs

c)

Focused on Assets

d)

Focused on Tasks

e)

Focused on Attackers

6.

What is a dictionary attack, and how does it work?

a)

An attempt to discover passwords by using every possible password in a predefined database or list of common or expected passwords.

b)

An attempt to discover passwords for user accounts by systematically attempting all possible combinations of letters, numbers, and symbols.

c)

An attempt to discover passwords by guessing a password randomly and checking whether it matches the stored hash value.

7.

What is access aggregation, and how can it be prevented?

a)

Access aggregation is a type of password attack

b)

Access aggregation is a method of collecting sensitive information

c)

Access aggregation cannot be prevented

d)

Access aggregation refers to collecting multiple pieces of nonsensitive information and combining them to learn sensitive information

8.

Do security methods attempt to prevent loss of confidentiality, loss of integrity, and loss of availability?

a)

False

b)

True

9.

The main difference between permissions, rights and privileges in the context of access control is that permissions and rights are interchangeable whereas privileges refer to the access granted to a specific object.

a)

True

b)

False

10.

How many Access Control Models should you understand when studying for the CISSP certification exam?

(a)