Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ISC2 - CC - Chapter 3 - Module 3

Total questions: 24

Worksheet time: 12mins

Name
Class
Date
1.
Which of the following is the definition of logical access controls?
a)
Authentication methods that manage access to systems
b)
Authentication methods that manage access to physical locations
c)
Any control that involves technology
d)
All the other answers are correct
2.
What is access control policy?
a)
A list of authorized users and their privileges
b)
A list of network devices and their configurations
c)
A set of guidelines and procedures for managing access to resources and data
d)
A list of resources and their security requirements
3.
What do protect logical access controls?
a)
Physical Assets
b)
Information
c)
All assets
d)
People
4.
Which of the following can never be considered a logical access control?
a)
PIN number
b)
Face pattern
c)
Fence
d)
USB key
5.
What is a security token?
a)
A type of Access Control Model
b)
A type of encryption algorithm
c)
A physical device used to store authentication credentials
d)
A type of biometric identifier
6.
What do access control models allow to assign in an efficient way?
a)
Authentication
b)
Authorization
c)
Non-repudiation
d)
Accounting
7.
What does authorization mean?
a)
The process of verifying user's identity
b)
The process of granting access to resources and data
c)
The process of creating a copy of backup
d)
The process of encrypting data
8.
Why do Access Control Models exists?
a)
Regulate access to resources
b)
Give permissions individually to people
c)
Authenticate users
d)
Control assets
9.
Which of the following is NOT an Access Control Model?
a)
Private Access Control (PAC)
b)
Role-based Access Control (RBAC)
c)
Attribute-based Access Control (ABAC)
d)
Mandatory Access Control (MAC)
10.
Which of the following access control models allows the creator of an object to delegate permissions?
a)
Discretionary Access Control (DAC)
b)
Role-based Access Control (RBAC)
c)
Mandatory Access Control (MAC)
d)
Attribute-based Access Control (ABAC)
11.
Which access control model are permissions determined by the resource owner, who has full control over granting or revoking access?
a)
Discretionary Access Control (DAC)
b)
Role-based Access Control (RBAC)
c)
Mandatory Access Control (MAC)
d)
Attribute-based Access Control (ABAC)
12.
Which of the following Access Control Models is better suit for small organizations?
a)
Role-based Access Control (RBAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Discretionary Access Control (DAC)
13.
Which of the following Access Control Models is based on predefined rules that can only be modified by security administrators?
a)
Role-based Access Control (RBAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Discretionary Access Control (DAC)
14.
Which of these Access Control Systems is commonly used in the military?
a)
Role-based Access Control (RBAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Discretionary Access Control (DAC)
15.
Which of these Access Control Systems is commonly used in governments?
a)
Role-based Access Control (RBAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Discretionary Access Control (DAC)
16.
Which access control model specifies access to an object based on the subject's role in the organization?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
17.
Which access control model assigns permissions based on job functions and responsibilities within an organization?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
18.
Which of the following Access Control Models is better suit for corporations?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
19.
Which access control model can grant access to a given object based on attributes?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
20.
Which of the following Access Control Models is better suit for large-complex industries like health or finance?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
21.
What is the most important difference between MAC and DAC?
a)
In MAC, security administrators set the roles for the users; in DAC, roles are set at the object owner’s discretion
b)
In MAC, access permissions are set at the object owner’s discretion; in DAC, it is up to security administrators to assign access permissions
c)
In MAC, security administrators assign access permissions; in DAC, security administrators set user roles
d)
In MAC, security administrators assign access permissions; in DAC, access permissions are set at the object owner’s discretion
22.
Mohammed has a company of 15 employees. He wants his employees to have the possiblity to share data if they need it so the workflow is not stopped. Which model would you recommend to mohammed?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
23.
An istitution needs a model which grants access based on security clearances, and users can only access information relevant to their assigned tasks.
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)
24.
Which access control model is more likely to be used for a bank?
a)
Discretionary Access Control (DAC)
b)
Mandatory Access Control (MAC)
c)
Attribute-based Access Control (ABAC)
d)
Role-based Access Control (RBAC)