wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Access Controls Quiz

Total questions: 71

Worksheet time: 39mins

Name
Class
Date
1.

Involves limiting what objects can be available to what subjects according to what rules

a)

Access Control

b)

Subjects

c)

Rule

d)

Object

2.

Any entity that requests access to our assets

Example: A ___ is the initiator of a request for service; therefore, a ___ is referred to as "active".

a)

Subjects

b)

Object

c)

Rule

3.

A device, process, person, user, program, server; client or other entity that responds to a request for service.

Example: An ___ has an owner, and the owner has the right to determine who or what should be allowed access to their ___.

a)

Object

b)

Rule

c)

Subject

4.

An instruction developed to allow or deny access to an object by comparing the validated identity of the subject to an access control list.

Example: When a user (subject) attempts to access a file (object), a ___ validated the level of access, if any, the user should have to that file.

a)

Rule

b)

Object

c)

Subject

5.

Access is based on three elements:

a)

Subject

Object

Rule

b)

Badge Systems and Gate Entry

Environment Design

Biometrics

c)

Natural Surveillance

Natural Access Control

Natural Territory Reinforcement

6.

Describes an information security strategy that integrates people, technology and operations capabilities to establish variable barriers across multiple layers and missions of the organization.

a)

Defense in Depth

b)

The Principle of Least Privilege (NIST SP 800-179)

c)

Privileged Access Management

d)

Privileged Accounts

7.

Is a standard of permitting only minimum access necessary for users or programs to fulfill their function

a)

The Principle of Least Privilege (NIST SP 800-179)

b)

Privileged Access Management

c)

Privileged Accounts

d)

Segregation of Duties

8.

Includes role-based specific subsets of privileges that only become active in real time when the identity is requesting the use of a resource or service.

a)

Privileged Access Management

b)

Privileged Accounts

c)

Segregation of Duties

d)

Two-person rule

9.

Are those of normal users, such as managers and administrators

a)

Privileged Accounts

b)

Privileged Access Management

c)

Segregation of Duties

d)

Two-person rule

10.

Record of the events occurring within an organization's systems and networks

a)

Logging

b)

Audited

c)

Segregation of Duties

d)

Two-person rule

11.

To ensure compliance with established policies and operational procedures

a)

Audited

b)

Logging

c)

Segregation of Duties

d)

Two-person rule

12.

Based on the security practice that no one person should control an entire high-risk transaction from start to finish

a)

Segregation of Duties

b)

Two-person rule

c)

Physical access controls

d)

Separation of employment

13.

A security strategy that requires a minimum of two people to be in an area together, making it impossible for a person to be in the area alone

a)

Two-person rule

b)

Segregation of Duties

c)

Separation of employment

d)

Physical access controls

14.

When employees leave the company, depending on company policy and procedures, their accounts must be disable after the termination data and time

a)

Separation of employment

b)

A new employee

c)

Change of position

15.

Are items you can physical touch.

Example: Prevent, monitor, or detect direct contact with systems or areas within a facility

a)

Physical access controls

b)

Verification

c)

Logical access controls

d)

Discretionary Access Control (DAC)

16.

Types of Physical Access Controls:

a)

Badge Systems and Gate Entry

Environment Design

Biometrics

b)

Natural Surveillance

Natural Access Control

Natural Territory Reinforcement

c)

Subject

Object

Rule

17.

The user presents their biometric data to the system so that the biometric data can be compared with the stored biometric code

a)

Verification

b)

Logical access controls

c)

Discretionary Access Control

d)

Mandatory Access Control (MAC)

18.

Monitoring Personnel:

a)

Cameras

Logs

Security Guards

Alarm Systems

b)

Passwords

Biometrics (implemented on a system, such as a smartphone or laptop)

Badge/token readers connected to a system

c)

Pull permissions list

Review with managers

Make adjustments

19.

Are electronic methods that limit some from getting access to systems, and sometimes even to tangible assets or areas.

a)

Logical access controls

b)

Discretionary Access Control (DAC)

c)

Mandatory Access Control (MAC)

d)

Role-Based Access Control (RBAC)

20.

Enforced over all subjects and objects in an information system

a)

Discretionary Access Control (DAC)

b)

Mandatory Access Control (MAC)

c)

Role-Based Access Control (RBAC)

21.

Uniformly enforced across all subjects and objects within the boundary of an information system

a)

Mandatory Access Control (MAC)

b)

Role-Based Access Control (RBAC)

c)

Discretionary Access Control (DAC)

22.

Provides each worker privileges based on what role they have in the organization. Only Human Resources staff have access to personnel files.

a)

Role-Based Access Control (RBAC)

b)

Mandatory Access Control (MAC)

c)

Discretionary Access Control (DAC)

23.

Plays an important role in protecting information and systems

a)

Physical security

b)

Data centers

c)

Server rooms

d)

Media storage facilities

24.

Contain massive quantities of valuable information and computing resources

a)

Data centers

b)

Server rooms

c)

Media storage facilities

d)

Evidence storage

25.

Contain sensitive information in less secure locations

a)

Server rooms

b)

Media storage facilities

c)

Evidence storage

d)

Wiring closets

26.

Require additional attention, particularly if in remote locations

a)

Media storage facilities

b)

Evidence storage

c)

Wiring closets

d)

Distribution cabling

27.

Locations must preserve the chain of custody

a)

Evidence storage

b)

Wiring closets

c)

Distribution cabling

d)

Physical security

28.

Offer access to eavesdroppers and network intruders

a)

Wiring closets

b)

Distribution cabling

c)

Physical security

d)

Data centers

29.

Don't forget about (a)   centers and other sensitive locations

30.

Allow you to focus security controls

a)

Gates

b)

Bollards

c)

Visit Management Procedures

d)

Two Person Integrity

31.

Provides direction to solve the challenges of crime with organizational (people), mechanical (technology and hardware) and natural designed (architectural and circulation flow) method.

a)

Crime Prevention Through Environmental Design

b)

Visitor Management Procedures

c)

Two Person Integrity

d)

Two Person Control

32.

When a new employee is hired, the hiring manager sends a request to the security administrator to create new user ID.

a)

A new employee

b)

Change of position

c)

Separation of employment

33.

When an employee has been promoted, their permissions and access rights might change as defined by the new role, which will dictate any added privileges and update to access.

a)

Change of position

b)

A new employee

c)

Separation of employment

34.

CPTED Goals:

a)

Natural Surveillance

Natural Access Control

Natural Territory Reinforcement

b)

Describe allowable visit purposes

Explain visit approval authority

Describe requirements for unescorted access

Explain role of visitor escorts

c)

Pull permissions list

Review with managers

Make adjustments

d)

Watch for suspicious activity

Alert administrators to anomalies

35.

Protect against intrusions

a)

Visitor Management Procedures

b)

Job rotation

c)

Mandatory vacation policies

d)

Two-Person Control

36.

Visitor Procedures:

a)

Describe allowable visit purposes

Explain visit approval authority

Describe requirements for unescorted access

Explain role of visitor escorts

b)

Natural Surveillance

Natural Access Control

Natural Territory Reinforcement

c)

Impossible travel time logins

Unusual network location logins

Unusual time-of-day logins

Deviations from normal behavior

Deviations in volume of data transferred

37.

All visitor access to secure areas should be logged

a)

True

b)

False

38.

(a)   should be clearly identified with distinctive badges

39.

(a)   provide an added degree of monitoring in visitor areas

40.

(a)   play a crucial role in physical security

41.

(a)   may act as security guards

42.

Although a menacing look is sometimes desirable

a)

True

b)

False

43.

(a)   sentries may replace human security patrols

44.

Two people must enter sensitive areas together

a)

Two Person Integrity

b)

Two Person Control

c)

Job rotation

d)

Mandatory vacation policies

45.

Two people must jointly approve sensitive actions

a)

Two Person Control

b)

Two Person Integrity

c)

Job rotation

d)

Mandatory vacation policies

46.

Moves employees through different positions

a)

Job rotation

b)

Mandatory vacation policies

c)

Inaccurate Permissions

d)

Privilege Creep

47.

Require time away from work

a)

Mandatory vacation policies

b)

Inaccurate Permissions

c)

Privilege Creep

d)

Account Audits

48.

(a)   Convention:

Kayla Mann -> Kmann or Kmann777

49.

Block work and/or violate least privilege

a)

Inaccurate Permissions

b)

Privilege Creep

c)

Account Audits

d)

Prioritize reviews

50.

A condition when users switch jobs and gain new permissions but never have their old permissions revoked

a)

Privilege Creep

b)

Account Audits

c)

Prioritize reviews

d)

Attestation reviews

51.

Protect against inaccurate permissions

a)

Account Audits

b)

Prioritize reviews

c)

Attestation reviews

d)

Unauthorized use

52.

User Account Audits:

a)

Pull permissions list

Review with managers

Make adjustments

b)

Badge Systems and Gate Entry

Environment Design

Biometrics

c)

Natural Surveillance

Natural Access Control

Natural Territory Reinforcement

53.

Users with changed jobs

a)

Prioritize reviews

b)

Attestation reviews

c)

Unauthorized use

54.

Formal approval documentation

a)

Attestation reviews

b)

Prioritize reviews

c)

Unauthorized use

55.

Permissions by legitimate users

a)

Unauthorized use

b)

Attestation reviews

c)

Prioritize reviews

56.

Continuous Account Monitoring:

a)

Watch for suspicious activity

Alert administrators to anomalies

b)

Prevents users from accessing resources without permission

Is especially critical when a user leaves under adverse circumstances

c)

May inform a user in advance of pending termination

May allow a user access to resources after termination

57.

Access Policy Violations:

a)

Impossible travel time logins

Unusual network location logins

Unusual time-of-day logins

Deviations from normal behavior

Deviation in volume of data transferred

b)

Describe allowable visit purposes

Explain visit approval authority

Describe requirements for unescorted access

Explain role of visitor escorts

c)

Natural Surveillance

Natural Access Control

Natural Territory Reinforcement

58.

Adds user location information to logs

a)

Geotagging

b)

Geofencing

c)

Provisioning

d)

Deprovisioning

59.

Alerts when a device leaves defined boundaries

a)

Geofencing

b)

Geotagging

c)

Provisioning

d)

Deprovisioning

60.

A crucial identity and access management task

a)

Provisioning and Deprovisioning Accounts

b)

Routine Workflow

c)

Emergency Workflow

d)

Authorization

61.

After onboarding, administrators create authentication credentials and grant appropriate authorization

a)

Provisioning

b)

Deprovisioning

c)

Inaccurate Permissions

d)

Privilege Creep

62.

During offboarding process, administrators disable accounts and revoke authorizations at the appropriate time

a)

Deprovisioning

b)

Provisioning

c)

Least Privilege

d)

Routine Workflow

63.

Prompt Termination is Critical:

a)

Prevents users from accessing resources without permission.

Is especially critical when a user leaves under adverse circumstances.

b)

May inform a user in advance of pending termination

May allow a user access to resources after termination

c)

Watch for suspicious activity

Alert administrators to anomalies

64.

Disables accounts on a scheduled basis for planned departures

a)

Routine Workflow

b)

Emergency Workflow

c)

Authorization

d)

Least Privilege

65.

Immediately suspends access when user is unexpectedly terminated

a)

Emergency Workflow

b)

Routine Workflow

c)

Authorization

d)

Least Privilege

66.

Incorrectly Timed Account Revocations:

a)

May inform a user in advance of pending termination

May allow a user access to resources after termination

b)

Watch for suspicious activity

Alert administrators to anomalies

c)

Prevents users from accessing resources without permission.

Is especially critical when a user leaves under adverse circumstances.

67.

Determines what an authenticated user can do

a)

Authorization

b)

Least Privilege

c)

Mandatory Access Control (MAC)

d)

Discretionary Access Control (DAC)

68.

Says that the user should have the minimum set of permissions necessary to perform their job

a)

Least Privilege

b)

Mandatory Access Control (MAC)

c)

Discretionary Access Control (DAC)

d)

Role-based Access Control (RBAC)

69.

In a ___ system, permissions are determined by the system.

a)

Mandatory Access Control (MAC)

b)

Discretionary Access Control (DAC)

c)

Role-based Access Control (RBAC)

70.

In a ___ system, permissions are determined by file owners

a)

Discretionary Access Control (DAC)

b)

Mandatory Access Control (MAC)

c)

Role-based Access Control (RBAC)

71.

Grants permissions to groups of people

a)

Role-based Access Control (RBAC)

b)

Mandatory Access Control (MAC)

c)

Discretionary Access Control (DAC)