wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISC3 - Domain 3 - Access Control Concepts

Total questions: 28

Worksheet time: 14mins

Name
Class
Date
1.

Which of the following is an example of security control?

a)

Computer mouse

b)

Firewall

c)

Network cable

d)

Web browser

2.

What is the definition of an object in the context of access controls?

a)

A device with onboard firmware

b)

An entity that responds to a request for service

c)

Anything that initiates a request for service

d)

Something that contains its own access control logic

3.

Derrick logs on to a system to read a file.  In this example, Derrick is the ______.

a)

Object

b)

Predicate

c)

Process

d)

Subject

4.

Which of the following is a subject?

a)

Fence

b)

File

c)

Filename

d)

User

5.

What is the strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of an organization?

a)

Cyberattack Prevention

b)

Layered Defense

c)

Multi-Factor Authentication

d)

Single Point of Failure

6.

How does privileged access management implement the principle of least privilege?

a)

By granting each user access only to the items they need

b)

By granting maximum access to all users

c)

By providing access based on seniority

d)

By restricting access to only the most critical information

7.

In Mandatory Access Control (MAC), what determines the level of access to certain areas in certain government agencies?

a)

Government policy and security clearance

b)

Individual judgment

c)

On a request basis

d)

Owner's discretion

8.

Which of the following is an example of a logical access control method?

a)

Biometrics on a smartphone

b)

Cameras

c)

Security guards

d)

Turnstiles

9.

Limiting access to data on the network would be considered which of the following controls?

a)

Administrative controls

b)

Logical or technical controls

c)

Physical controls

d)

Virtualization controls

10.

What would be considered an administrative control in the context of seat belt usage?

a)

Attaching the seat belt to the car

b)

Building a car with seat belts

c)

Passing a law requiring seat belt use

d)

Using the seat belt

11.

What alternative control could be used if biometric locks on multiple doors are not necessary and access does not need to be audited?

a)

Implementing biometric scanners on all doors

b)

Installing a permanent wall

c)

Removing doors and securing the area permanently

d)

Replacing doors with deadbolt locks

12.

In what type of environment does role-based access control work well?

a)

High-staff turnover and similar access requirements

b)

Limited access requirements for all personnel

c)

Low-staff turnover

d)

Single personnel with unique access requirements

13.

What term is used to describe the situation where someone inherits expanded permissions that are not appropriate for their role in Role-based Access Control (RBAC)?

a)

Access overflow

b)

Permissions anomaly

c)

Privilege creep

d)

Role deviation

14.

What is the key feature of just-in-time privileged access management?

a)

Permanent administrative access

b)

Role-based subsets of privileges

c)

Static privileges

d)

Unrestricted access

15.

Why is it recommended to disable accounts for a period before deletion when an employee leaves the company?

a)

So the ex-employee can't steal secrets

b)

To allow the separated employee access to data

c)

To preserve the integrity of audit trails or files

d)

To speed up the account deletion process

16.

Who can modify security rules in a system governed by Mandatory Access Control (MAC)?

a)

All subjects within the system

b)

Object owners at their discretion

c)

Randomly selected users

d)

Trusted subjects designated as security administrators

17.

Which of these combinations of physical security controls share a single point of failure?

a)

Badge readers and walls

b)

Dogs and bollards

c)

Guards and fences

d)

High-illumination lighting and cameras

18.

What challenges do small and medium businesses face regarding technical controls in payroll systems?

a)

Inadequate physical controls

b)

Insufficient personnel for duty separation

c)

Lack of administrative controls

d)

Limited availability requirements

19.

Which of the following is an example of a physical access control?

a)

Antivirus software

b)

Encryption algorithms

c)

Firewalls

d)

Motion detectors

20.

Duncan and Mira work in the data center at Triffid, Inc. There is a policy in place that requires both to be present in the data center at the same time. If one has to leave for any reason, the other must step out, too, until they can both re-enter. This is called ________.

a)

Blockade

b)

Defense in depth

c)

Multifactor authentication

d)

Two-person integrity

21.

Why is Discretionary Access Control (DAC) not considered very scalable?

a)

It is a hardware-intensive approach

b)

It relies on mandatory access controls

c)

It relies on the discretion of individual object owners

d)

It uses advanced encryption techniques

22.

What is the two-person rule in the context of security strategy?

a)

Two people must be in an area together

b)

Two people must have access to the same information

c)

Two people must have the same combination

d)

Two people must perform the same duties

23.

What is user provisioning in identity management?

a)

Enabling the option to delete a users account

b)

Ensuring a user can always control what they want to access

c)

Ensuring that users are conducting regular antivirus scans

d)

Managing access to resources and information systems

24.

Lakshmi presents a user ID and a password to a system to log on. Which of the following characteristics must the password have?

a)

Confidential

b)

Mathematical

c)

Shared

d)

Unique

25.

What does behavioral biometrics measure?

a)

Characteristics like fingerprint and iris scan

b)

Environmental design elements

c)

Physiological attributes

d)

User actions, such as voiceprints and keystroke dynamics

26.

Which of the following is the responsibility of systems administrators who use privileged accounts?

a)

Handling customer service

b)

Managing financial transactions

c)

Marketing and promotions

d)

Operating systems and applications

27.

Which is a physical control that prevents "piggybacking" or "tailgating," when an unauthorized person follows an authorized person into a controlled area?

a)

Bollard

b)

Fence

c)

Turnstile

d)

Wall

28.

Which of the following is an example of a monitoring tool?

a)

Biometrics

b)

Cameras

c)

Passwords

d)

Turnstiles