wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ID and Access Management

Total questions: 70

Worksheet time: 35mins

Name
Class
Date
1.

What are the three principles of the CIA Triad?

a)

Confidentiality, Integrity, Availability

b)

Confidentiality, Innovation, Accessibility

c)

Control, Integrity, Access

d)

Communication, Information, Access

2.

What is the fundamental security goal of confidentiality?

a)

Keeping information accurate and free of errors

b)

Ensuring systems operate continuously

c)

Keeping information and communications private

d)

Ensuring data remains associated with its creator

3.

Which term refers to the security goal of ensuring data remains associated with its creator?

a)

Integrity

b)

Non-repudiation

c)

Availability

d)

Confidentiality

4.

What does the National Institute of Standards and Technology (NIST) do?

a)

Develops computer security standards and publishes best practice guides

b)

Provides funding for cybersecurity startups

c)

Offers online courses in cybersecurity

d)

Manufactures security hardware

5.

What is the purpose of security controls?

a)

To increase system speed

b)

To mitigate vulnerabilities and ensure CIA

c)

To enhance user interface design

d)

To reduce software costs

6.

What is the purpose of a gap analysis?

a)

To measure the difference between current and desired states in a project

b)

To identify security vulnerabilities in a system

c)

To track user activity in a network

d)

To determine user access rights

7.

What does identity and access management (IAM) provide?

a)

Data encryption and decryption

b)

Identification, authentication, and authorization mechanisms

c)

Network traffic monitoring

d)

System performance optimization

8.

What is the process of identification in access control?

a)

Validating a user's credentials

b)

Issuing a user account to the correct person

c)

Determining user access rights

d)

Monitoring user activity

9.

What is the role of authentication in security?

a)

To encrypt data

b)

To validate an entity's unique credentials

c)

To monitor network traffic

d)

To manage user permissions

10.

What does authorization determine in access control?

a)

The encryption method used

b)

The rights and privileges a user has

c)

The network speed

d)

The type of data stored

11.

What is the function of accounting in security?

a)

Encrypting data

b)

Tracking authorized usage and alerting unauthorized use

c)

Managing user permissions

d)

Optimizing system performance

12.

What does the authentication, authorization, and accounting (AAA) model ensure?

a)

Data encryption

b)

Centralized verification and audit trail creation

c)

Network speed optimization

d)

System performance monitoring

13.

What is the role of the control plane in zero trust architecture?

a)

Encrypting data

b)

Defining policy and determining access decisions

c)

Monitoring network traffic

d)

Managing user accounts

14.

What do permissions control in a security setting?

a)

Network speed

b)

Access to objects including file system items and network resources

c)

Data encryption methods

d)

System performance

15.

What is a characteristic of discretionary access control (DAC)?

a)

Resources are protected by system-defined rules

b)

Each resource is protected by an access control list managed by the owner

c)

Access is granted based on user roles

d)

Resources are encrypted by default

16.

What defines mandatory access control (MAC)?

a)

User-defined access rules

b)

Inflexible, system-defined rules

c)

Role-based access permissions

d)

Dynamic access adjustments

17.

What is Role-based access control (RBAC)?

a)

An access control model where resources are protected by ACLs and managed by administrators based on job functions.

b)

A model that evaluates a set of attributes to determine access.

c)

A nondiscretionary access control technique based on operational rules.

d)

A process of deploying an account to a production environment.

18.

What is the purpose of a group account?

a)

To evaluate a set of attributes for access.

b)

To establish file permissions and user rights for many individuals needing the same level of access.

c)

To deploy an account to a production environment.

d)

To identify the physical location of an object.

19.

What does Attribute-based access control (ABAC) evaluate?

a)

The physical location of an object.

b)

A set of attributes each subject possesses to determine access.

c)

The value assigned to an account by Windows.

d)

The process of removing an account from a production environment.

20.

What is the principle of Least privilege?

a)

Allocating the maximum necessary rights and privileges.

b)

Allocating the minimum necessary rights, privileges, or information to perform a role.

c)

Deploying an account to a production environment.

d)

Identifying the physical location of an object.

21.

What is the process of Provisioning?

a)

Removing an account from a production environment.

b)

Deploying an account, host, or application to a target production environment with credentials and access permissions.

c)

Evaluating a set of attributes for access.

d)

Identifying the physical location of an object.

22.

What is the purpose of a time-of-day restrictions policy?

a)

To enhance device performance

b)

To limit a user's access to resources

c)

To increase network speed

d)

To provide data encryption

23.

Which of the following is NOT a fundamental security concept mentioned in the CompTIA Security+ SYO-701 objectives?

a)

Confidentiality, Integrity, and Availability (CIA)

b)

Non-repudiation

c)

Zero trust

d)

Data encryption

24.

What is included in the Zero Trust model under the control plane?

a)

Implicit trust zones

b)

Adaptive identity

c)

Identity proofing

d)

Access controls

25.

Which of the following is a mitigation technique used to secure the enterprise?

a)

Data encryption

b)

Access control

c)

Network segmentation

d)

Firewall configuration

26.

What is involved in implementing and maintaining identity and access management?

a)

Data encryption

b)

Network monitoring

c)

Provisioning/de-provisioning user accounts

d)

Software updates

27.

Which of the following is an example of an access control model?

a)

Mandatory

b)

Encryption

c)

Firewall

d)

Antivirus

28.

What is a factor used in multifactor authentication?

a)

Something you know

b)

A password manager

c)

A firewall

d)

An antivirus software

29.

Which of the following is a type of authentication token?

a)

Hard/soft authentication tokens

b)

Password manager

c)

Encryption key

d)

Firewall rule

30.

What is an element of effective security governance?

a)

Information security policies

b)

Antivirus software

c)

Firewall configuration

d)

Password length

31.

What is multi-factor authentication (MFA)?

a)

An authentication scheme that requires only one factor

b)

A method that uses a password only

c)

An authentication scheme that requires at least two different factors

d)

A system that uses only biometric data

32.

Which of the following is an example of a "something you have" authentication type?

a)

Password

b)

Smart card

c)

Fingerprint

d)

Voice recognition

33.

What is a personal identification number (PIN) used for in authentication?

a)

To store biometric data

b)

To be shared with others for access

c)

To be used in conjunction with authentication devices like smart cards

d)

To replace passwords entirely

34.

What is a hard authentication token?

a)

A password stored on a server

b)

An authentication token generated by a cryptoprocessor on a dedicated hardware device

c)

A biometric scanner

d)

A simple key card

35.

What is a one-time password (OTP)?

a)

A password that is used for multiple sessions

b)

A password that is generated for use in one specific session and becomes invalid after the session ends

c)

A password that is stored permanently

d)

A password that is shared among users

36.

What is a security key used for?

a)

Single-factor authentication

b)

Multi-factor authentication

c)

Password storage

d)

Data encryption

37.

What does a soft authentication token involve?

a)

A physical key

b)

A password manager

c)

An OTP sent to a registered number or email account

d)

A biometric scan

38.

What is the main feature of a passwordless authentication scheme?

a)

It uses only passwords

b)

It uses ownership and biometric factors, but not knowledge factors

c)

It requires a security question

d)

It relies on email verification

39.

What is the purpose of attestation in authentication?

a)

To encrypt data

b)

To prove that a device or computer is a trustworthy platform

c)

To store user passwords

d)

To manage network traffic

40.

What is NT LAN Manager (NTLM) authentication?

a)

A password storage system

b)

A challenge-response authentication protocol created by Microsoft

c)

A data encryption method

d)

A network monitoring tool

41.

What is a pluggable authentication module (PAM)?

a)

A hardware device for authentication

b)

A framework for implementing authentication providers in Linux

c)

A type of password manager

d)

A network security protocol

42.

What is the function of a directory service?

a)

To encrypt files

b)

To store identity information about all the objects in a particular network

c)

To manage email accounts

d)

To monitor network traffic

43.

What does Lightweight Directory Access Protocol (LDAP) do?

a)

Encrypts data

b)

Accesses network directory databases to store information about authorized users

c)

Manages network traffic

d)

Provides internet access

44.

What is a distinguished name (DN) in a directory?

a)

A type of password

b)

A collection of attributes that define a unique identifier for any given resource within an X.500-like directory

c)

A network protocol

d)

A data encryption method

45.

What is single sign-on (SSO) technology?

a)

A method to encrypt data

b)

A technology that enables a user to authenticate once and receive authorizations for multiple services

c)

A password storage system

d)

A network monitoring tool

46.

What is Kerberos?

a)

A single sign-on authentication and authorization service based on a time-sensitive, ticket-granting system.

b)

A file format that uses attribute-value pairs.

c)

An XML-based web services protocol.

d)

A standardized, stateless architectural style.

47.

What does a Key Distribution Center (KDC) do in Kerberos?

a)

It authenticates users and issues tickets (tokens).

b)

It provides a shared login capability.

c)

It is used to exchange authentication information.

d)

It defines configurations in a structure.

48.

What is a Ticket Granting Ticket (TGT) in Kerberos?

a)

A token issued to an authenticated account to allow access to authorized application servers.

b)

A service that holds the user account and performs authentication.

c)

A protocol used to exchange messages.

d)

A file format for attribute-value pairs.

49.

What is the purpose of Federation in identity management?

a)

To provide a shared login capability across multiple systems and enterprises.

b)

To authenticate users and issue tickets.

c)

To define configurations in a structure.

d)

To perform a biometric scan.

50.

What role does an Identity Provider (IdP) play in a federated network?

a)

It holds the user account and performs authentication.

b)

It issues tickets to users.

c)

It is used to exchange authentication information.

d)

It defines configurations in a structure.

51.

What is Security Assertion Markup Language (SAML)?

a)

An XML-based data format used to exchange authentication information between a client and a service.

b)

A protocol used to exchange messages.

c)

A file format for attribute-value pairs.

d)

A standardized, stateless architectural style.

52.

What is Simple Object Access Protocol (SOAP)?

a)

An XML-based web services protocol that is used to exchange messages.

b)

A file format for attribute-value pairs.

c)

A standardized, stateless architectural style.

d)

A biometric authentication mechanism.

53.

What is Representational State Transfer (REST)?

a)

A standardized, stateless architectural style used by web applications for communication and integration.

b)

A protocol used to exchange messages.

c)

A file format for attribute-value pairs.

d)

An authentication mechanism using biometrics.

54.

What is Open Authorization (OAuth)?

a)

A standard for federated identity management, allowing resource servers or consumer sites to work with user accounts created and managed on a separate identity provider.

b)

A protocol used to exchange messages.

c)

A file format for attribute-value pairs.

d)

An XML-based data format.

55.

What is JavaScript Object Notation (JSON)?

a)

A file format that uses attribute-value pairs to define configurations in a structure that is easy for both humans and machines to read and consume.

b)

An XML-based data format.

c)

A protocol used to exchange messages.

d)

A biometric authentication mechanism.

56.

What is biometric authentication?

a)

An authentication mechanism that allows a user to perform a biometric scan to operate an entry or access system.

b)

A file format for attribute-value pairs.

c)

A protocol used to exchange messages.

d)

A standardized, stateless architectural style.

57.

What does the False Rejection Rate (FRR) measure in biometric systems?

a)

A biometric assessment metric that measures the number of valid subjects who are denied access.

b)

A biometric assessment metric that measures the number of unauthorized users who are mistakenly allowed access.

c)

A biometric evaluation factor expressing the point at which FAR and FRR meet.

d)

A metric indicating the speed of biometric processing.

58.

What is the False Acceptance Rate (FAR) in biometric systems?

a)

A biometric assessment metric that measures the number of unauthorized users who are mistakenly allowed access.

b)

A biometric assessment metric that measures the number of valid subjects who are denied access.

c)

A biometric evaluation factor expressing the point at which FAR and FRR meet.

d)

A metric indicating the accuracy of biometric data storage.

59.

Which of the following is NOT a component of the CIA triad in security concepts?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

60.

What is the purpose of the Zero Trust model in security?

a)

To ensure implicit trust zones and policy enforcement points.

b)

To allow unrestricted access to all users.

c)

To focus solely on external threats.

d)

To eliminate the need for authentication.

61.

Which of the following is NOT a type of access control mentioned in the document?

a)

Mandatory

b)

Discretionary

c)

Biometric

d)

Role-based

62.

What is an example of a factor used in multi-factor authentication?

a)

Something you know

b)

Something you eat

c)

Something you see

d)

Something you hear

63.

Which of the following is a component of effective security governance?

a)

User interface design

b)

Information security policies

c)

Network speed

d)

Software updates

64.

What is the definition of Authorization?

a)

Granting a user the right to use a resource on a computer system.

b)

A collection of access control entries.

c)

Access rights that are cumulative.

d)

Permissions that always override Allow permissions.

65.

What does an Access Control List (ACL) determine?

a)

The right to use a resource.

b)

Which users are allowed or denied access to an object.

c)

Cumulative access rights.

d)

Permissions that override Allow permissions.

66.

What are Effective Permissions?

a)

Granting a user the right to use a resource.

b)

A collection of access control entries.

c)

Cumulative access rights from multiple groups.

d)

Permissions that always override Allow permissions.

67.

What do Deny Permissions do?

a)

Grant a user the right to use a resource.

b)

Determine which users are allowed or denied access.

c)

Override Allow permissions.

d)

Provide cumulative access rights.

68.

What does ACL stand for in the context of access control?

a)

Access Control List

b)

Access Configuration Log

c)

Application Control Layer

d)

Authentication Control Level

69.

Which of the following is a method of access control that involves assigning permissions?

a)

Discretionary Access Control

b)

Mandatory Access Control

c)

Role-based Access Control

d)

Single Sign-On

70.

What does SSO stand for in identity and access management?

a)

Single Sign-On

b)

Secure Sign-Off

c)

System Security Operations

d)

Simple Security Option