NEW
Font size
WorksheetsAAQ IT Hardware & software security
Total questions: 25
Worksheet time: 13mins
Which example best represents a knowledge-based authentication factor?
Smart card with embedded chip
Fingerprint captured by a sensor
Password remembered by the user
Phone used for hardware token codes
Which factor category includes fingerprints, face scans, or iris patterns?
Something you have
Somewhere you are
Something you are
Something you know
A one-time code generated by an authenticator app is primarily which factor?
Something you have
Something you know
Something you are
Somewhere you are
In Discretionary Access Control (DAC), who typically decides object access?
System administrator only
Object owner determines permissions
Central policy engine enforces rules
Role manager assigns privileges
Rule-Based Access Control (RuBAC) decisions are driven by:
Static user role mappings
Physical possession of tokens
Defined policies and conditions
Ad hoc owner preferences
Which scenario best fits RBAC?
Nurse role gets patient-chart view
Token required for VPN access
File owner sets read access
Policy denies after hours login
Which measure helps recover a lost smartphone?
Uninstalling password manager
Removing biometric authentication
GPS-based device tracking service
Disabling all wireless radios
What is the primary purpose of device tracking software?
Encrypt files for data sharing
Block all incoming network traffic
Locate and recover lost devices
Optimize battery health data
In DAC, what is a likely security weakness?
Owner may grant overly broad access
Rigid role definitions everywhere
Tokens always expire after issuance
Policies automatically block risks
In RBAC, what must be managed to keep least privilege?
Device screen brightness levels
Roles and permission assignments
Owner’s mood and preferences
Global GPS location accuracy
Which measure improves recovery odds before loss occurs?
Disable location services everywhere
Use only single-factor passwords
Share login details for backup
Preconfigure tracking and remote wipe
Which access control model simplifies onboarding in large organizations?
DAC with per-file decisions
No model with open permissions
RBAC with role-based permissions
RuBAC with hourly conditions
After enabling tracking, which next step helps recovery?
Contact authorities with live location
Share location publicly with everyone
Immediately post device to social media
Disable SIM and tracking services
Which best explains least privilege under RBAC?
Grant all rights by default
Assign only necessary role permissions
Let owners decide case by case
Allow access based on time alone
Security tokens primarily improve security by:
Storing longer passwords for faster logins
Blocking all network connections by default
Tracking user activity for auditing reports
Requiring possession of a physical device to access
Which example best represents the location factor in authentication?
Matching a facial scan during login
Plugging in a smartcard to a reader
Answering security questions from memory
Verifying sign-in from a usual GPS position
Which model lets the resource owner decide who can read or modify a file, including changing its permissions?
Rule-based access control with strict criteria
Discretionary access control by the owner
Role-based access control with job tiers
Mandatory access control with labels
In a company, access to sensitive financial records is limited to accountants because of their job duties. Which control model is being used?
Rule-based control with user-specific rules
Role-based control tied to responsibilities
Discretionary control by file creators
Time-based control using schedules
Which statement best describes Rule-Based Access Control (RuBAC)?
Access depends on seniority and responsibilities
Owners grant permissions to their own resources
Administrators enforce predefined criteria rules
Labels and clearances determine every access
A lower-level employee tries to open a confidential budget file but is blocked because of their position. What most likely caused the denial?
RBAC restricted access based on role
DAC owner revoked all group permissions
Network segmentation blocked the request
RuBAC criteria did not match their profile
Which statement best describes Trusted Computing in secure environments?
Focuses mainly on physical locks and cable restraints
Depends on third-party apps for all security controls
Relies only on user passwords to block unauthorized access
Uses integrated hardware-software features to reduce threats
A school laptop should lock automatically after inactivity and after several failed logins. Which protection approach applies?
Trusted Computing with centralized audit-only logging
Software updates for the operating system kernel
Hardware-only controls like chassis intrusion switches
Device-Based Protection with timed auto-lock and lock-on failures
What is the primary purpose of a remote wipe when a device cannot be recovered?
Disable Wi‑Fi to save mobile data
Increase GPS accuracy for location
Erase data to prevent unauthorized access
Boost battery life during tracking
A phone is stolen and still connected to cellular and Wi‑Fi networks. Which approach best increases the chance of recovery without exposing data?
Share passwords with the carrier
Use Find the Device to track location
Disable GPS in phone settings
Immediately perform a remote wipe
Which is a commonly cited drawback of Trusted Computing systems?
Guaranteed system uptime for all users
Automatic compatibility with all software
Increased battery life on mobile devices
Potential vendor lock‑in and reduced user control
