WorksheetsAuthentication/Access Control/Enterprise Architecture
Total questions: 50
Worksheet time: 25mins
Which of the following is the term for the process of validating a subject's identity?
Authorization
Authentication
Auditing
Identification
An employee traveling in Europe for vacation submitted a ticket as they could not access their work email. Which policy does the company use?
Multi-factor authentication
Password age
Password management
Location-based authentication
A contractor only works for a company from 9 a.m. to 12 p.m. What kind of restriction could the company set up on the contractor's account to prevent using it outside that range?
Password restrictions
Mandatory access control
Location-based restrictions
Time-based restrictions
A cyber engineer conducts a multi-factor authentication (MFA) assessment of an organization's authentication security. What MFA philosophy uses knowledge factors and includes passphrases to gain access to systems?
Something you have
Somewhere you are
Something you know
Something you are
What type of password is maryhadalittlelamb?
Composition
Static
Passphrase
Cognitive
You assign access permissions so that users can only access the resources required to accomplish their specific work tasks. Which security principle are you complying with?
Principle of least privilege
Job rotation
Need to know
Cross-training
In which form of access control environment is access controlled by rules rather than identity?
Mandatory access control (MAC)
Discretionary access control (DAC)
Access control list (ACL)
Most client-server environments
What is the primary function of Active Directory as a centralized database in a network?
It provides internet access to all computers in the network.
It serves as a backup system for all files in the network.
It stores and organizes all user accounts and security information.
It manages the power supply to all computers in the network.
You are teaching new users about security and passwords. Which of the following is the BEST example of a secure password?
JoHnSmITh
Stiles_2031
8181952
T1a73gZ9!
The IT department of a corporation evaluates its security mechanisms to identify areas lacking sufficient protection. Which of the following techniques should the IT department employ?
Authorization models
Zero trust
Gap analysis
Non-repudiation
Which access control model is based on assigning attributes to objects and using Boolean logic to grant access based on the attributes of the subject?
Rule-based access control
Attribute-based access control (ABAC)
Role-based access control (RBAC)
Mandatory access control (MAC)
An IT department is using a technique to assess the differences in performance between their systems, looking to see if the systems meet the established requirements. Which of the following terms BEST describes the technique the IT department is using?
Authorization models
Non-repudiation
Gap analysis
Zero trust
You have implemented an access control method that only allows users who are managers to access specific data. Which type of access control model is being used?
Discretionary access control (DAC)
Mandatory access control (MAC)
Discretionary access control list (DACL)
Role-based access control (RBAC)
You have configured a security device in your network to fail-closed. Which of the following will happen when an attack occurs?
The device will block access or enter the most secure state available when it fails.
The device will act on behalf of a client when accessing resources over the internet when it fails.
The device will distribute network traffic across multiple servers when it fails.
The device will preserve network or host access when it fails.
Which technology is primarily used by smart cards to store digital signatures, cryptography keys, and identification codes?
Hashing algorithms
Public Key Infrastructure (PKI)
Blockchain technology
Secure Sockets Layer (SSL)
Advanced Encryption Standard (AES)
What is the process of controlling access to resources such as computers, files, or printers called?
Conditional access
Authorization
Mandatory access control
Authentication
Which of the following principles is implemented in a mandatory access control model to determine object access by classification level?
Clearance
Ownership
Need to know
Principle of least privilege
Separation of duties
Which of the following is the MOST common form of authentication?
Fingerprint
Photo ID
Password
Digital certificate on a smart card
When sending confidential data over a network, a company wants to ensure both parties involved cannot deny the validity of the transmitted data. Which security principle should they prioritize?
Non-repudiation
Authentication, authorization, and accounting (AAA)
Zero trust
Adaptive identity
Which of the following identifies the type of access that is allowed or denied for an object?
User rights
SACL
Permissions
DACL
Which of the following authentication methods specifically allows users to access multiple systems, applications, or websites using only a single set of credentials?
Attestation
Directory services
Federation
Single sign-on (SSO)
After a breach, an organization implements new multi-factor authentication (MFA) protocols. What MFA philosophy incorporates using a smart card or key fob to support authentication?
Something you are
Something you know
Somewhere you are
Something you have
An organization implements a new network infrastructure and plans to use an intrusion prevention system (IPS) for security. The IT manager wants to ensure that the IPS will continue to let traffic flow if it fails. Which failure mode should the IT manager configure the IPS?
Fail-closed
Active
Passive
Fail-open
What principle of an organization's information security system ensures that only authorized individuals can access sensitive data, the data remains unaltered during storage and transfer, and the data is always accessible when needed?
CIA triad
Authenticating people
Two-factor authentication
Access control list
An employee at a company frequently recycles old passwords when prompted for a password change. What feature of a password policy can prevent this?
Password complexity
Password history
Password length
Password age
You have hired ten new temporary employees to be with the company for three months. How can you make sure that these users can only log on during regular business hours?
Configure day/time restrictions in user accounts.
Configure account policies in Group Policy.
Configure account lockout in Group Policy.
Configure account expiration in user accounts.
One of your company's accountants submitted a ticket stating they could not access a particular section of the accounting software. Why might the accountant not have access to every part of the accounting software?
Licensing
Least privilege
DAC
MAC
After finding a corporate phone unattended in a local mall, an organization decides to enhance its multi-factor authentication (MFA) procedures. What MFA philosophy applies a location-based factor for authentication?
Something you know
Something you are
Something you have
Somewhere you are
Which form of access control is based on job descriptions?
Discretionary access control (DAC)
Role-based access control (RBAC)
Mandatory access control (MAC)
Attribute-based access control (ABAC)
In the context of the NIST Cybersecurity Framework, which function involves identifying, analyzing, containing, and eradicating threats to systems and data security?
Identify
Protect
Recover
Respond
Which of the following statements about honeyfiles are true? (Select two.)
Honeyfiles are designed to provide real data to the attacker.
Honeyfiles are named in a way that makes them attractive to hackers, enticing them to open or execute them.
Honeyfiles are used to block all types of malicious traffic.
Honeyfiles can only be created by system administrators.
Honeyfiles work with network intrusion detection systems (NIDs) and can help prevent false positives.
An IT team at a global pharmaceutical company has decided to implement a virtual private network (VPN) for remote employees to securely access internal company resources from home. Which of the following is a primary reason for this decision?
VPNs are designed for managing devices on IP networks.
VPNs provide secure command-line access and file transfer.
VPNs provide a direct connection to a single machine.
VPNs encrypt and encapsulate all traffic to create a secure tunnel.
Jessica needs to set up a firewall to protect her internal network from the internet. Which of the following would be the BEST type of firewall for her to use?
Stateful
Hardware
Tunneling
Software
You are deploying a brand new router. After you change the factory default settings, what should you do next?
Update the firmware.
Configure anti-spoofing rules.
Secure the configuration file.
Configure SSH to access the router configuration.
In a rapidly evolving IT environment, a cloud service provider offers various services to businesses, enabling them to store and process data securely. To enhance security, the provider regularly updates its systems and software. Despite these efforts, a security researcher discovers a previously unknown vulnerability in one of the cloud-specific applications, leaving customer data exposed to potential threats. In this scenario, which vulnerability is the security researcher likely to have found in the cloud-specific application?
Zero-day vulnerability
Network misconfiguration
SQL injection vulnerability
Cross-site scripting (XSS) vulnerability
Which of the following applies the appropriate policies in order to provide a device with the access it's defined to receive?
Authentication
Identity Services Engine
Authorization
Zero-trust security
Which of the following is the BEST device to deploy to protect your private network from a public untrusted network?
Hub
Router
Gateway
Firewall
A financial institution is processing transactions and wishes to improve its security posture. The institution divides its network into different sections to minimize risk while actively updating or retrieving transaction data. What method does the financial institution intend to use?
Segmentation
Virtual private network (VPN)
Network address translation (NAT)
Firewalling
An attacker was able to gain unauthorized access to a mobile phone and install a Trojan horse so that he or she could bypass security controls and reconnect later. Which type of attack is this an example of?
Privilege escalation
Replay
Backdoor
Social engineering
You are a cybersecurity specialist for a financial institution that is planning to enhance its network security. The institution has decided to adopt a defense in depth strategy. Which of the following approaches would BEST align with a defense in-depth strategy?
Implementing a complex array of different security technologies without considering their interaction or potential redundancies.
Implementing a single, robust firewall at the network perimeter and relying on this for all network security.
Implementing a single security measure, such as encryption, across all data and network traffic.
Implementing multiple security measures at different network layers, including firewalls, intrusion detection systems, and regular patch management.
You are a network architect for a rapidly growing startup. The startup is planning to expand its operations and is considering a major upgrade to its network architecture. Which of the following factors should be your primary consideration when designing the new network architecture?
Maximizing compute resources and responsiveness, regardless of cost.
Balancing costs, compute and responsiveness, scalability, availability, and resilience.
Minimizing initial capital outlay by choosing the cheapest available hardware and software options.
Prioritizing scalability and ease of deployment over all other considerations.
Which of the following describes how access control lists can be used to improve network security?
An access control list filters traffic based on the frame header, such as source or destination MAC address.
An access control list looks for patterns of traffic between multiple packets and takes action to stop detected attacks.
An access control list filters traffic based on the IP header information, such as source or destination IP address, protocol, or socket number.
An access control list identifies traffic that must use authentication or encryption.
Which of the following BEST describes zero-trust security?
All devices are trusted.
Only devices that pass authorization are trusted.
Only devices that pass authentication are trusted.
Only devices that pass both authentication and authorization are trusted.
Which of the following should be configured on the router to filter traffic at the router level?
Access control list
Telnet
Anti-spoofing rules
SSH
In an effort to increase the security of your organization, programmers have been informed they can no longer bypass security during development. Which vulnerability are you attempting to prevent?
Privilege escalation
Social engineering
Backdoor
Replay
Which VPN tunnel style routes only certain types of traffic?
Split
Site-to-site
Full
Host-to-host
A VPN is primarily used for which of the following purposes?
Support secured communications over an untrusted network
Support the distribution of public web documents
Allow remote systems to save on long-distance charges
Allow the use of network-attached printers
Which VPN implementation uses routers on the edge of each site?
Remote access VPN
Host-to-host VPN
Site-to-site VPN
Always-on VPN
Which of the following defines all the prerequisites a device must meet in order to access a network?
Authorization
Authentication
Zero-trust security
Identity Services Engine (ISE)
Which of the following NAC agent types would be used for IoT devices?
Permanent
Zero-trust
Dissolvable
Agentless
