• Home
  • Textbooks
  • The SSCP Prep Guide: Mastering the Seven Key Areas of System Security
  • Domain 1: Access Controls

The SSCP Prep Guide: Mastering the Seven Key Areas of System Security

Debra S. Isaac, Michael J. Isaac

Chapter 2

Domain 1: Access Controls - all with Video Answers

Educators


Chapter Questions

Problem 1

A user providing a password to a system is involved with:
a. Evaluation
b. Identification
c. Authentication
d. Authorization

Check back soon!

Problem 2

The proactive approach to access control emphasizes which one of the following triples?
a. Prevention, detection, confirmation
b. Detection, correction, identification
c. Prevention, detection, authentication
d. Prevention, detection, reaction

Check back soon!

Problem 3

Kerberos is an authentication scheme that uses which of the following technologies?
a. Public key cryptography
b. Digital signatures
c. Private key cryptography
d. Factoring of large numbers

Check back soon!

Problem 4

A denial of service (DoS) attack can be implemented by:
a. Trying all possible combinations of words to break a password
b. Sending large amounts of unsolicited messages
c. Overwhelming the input of an information system to the point where it can no longer properly process the data
d. Posing as a known, trusted source

Check back soon!

Problem 5

The number of times that a password should be changed is a function of:
a. The critical nature of the information to be protected
b. The user's memory
c. The strength of the user's cryptography
d. The type of workstation used

Check back soon!

Problem 6

The three standard means of access control are:
a. Physical, preventive, and logical (technical)
b. Administrative, physical, and mandatory
c. Administrative, logical (technical), and discretionary
d. Physical, logical (technical), and administrative

Check back soon!

Problem 7

A database View operation implements the principle of:
a. Least privilege
b. Separation of duties
c. Entity integrity
d. Referential integrity

Check back soon!
01:11

Problem 8

A synchronous password generator:
a. Generates a password that must be used within a variable time interval
b. Generates a password that must be used within a fixed time interval
c. Generates a password that is not dependent on time
d. Generates a password that is of variable length

Emily Himsel
Emily Himsel
Numerade Educator

Problem 9

Access control is concerned with:
a. Threats, assets, and objectives
b. Vulnerabilities, secret keys, and exposures
c. Threats, vulnerabilities, and risks
d. Exposures, threats, and countermeasures

Check back soon!

Problem 10

The type of access control that is used in local, dynamic situations where subjects have the ability to specify what resources certain users can access is called:
a. Mandatory access control
b. Rule-based access control
c. Sensitivity-based access control
d. Discretionary access control

Check back soon!

Problem 11

Which of the following types of access control is preferred when there are frequent personnel changes in an organization?
a. Mandatory
b. Role-based
c. Rules-based
d. User-based

Check back soon!

Problem 12

Using symmetric key cryptography, Kerberos authenticates clients to other entities on a network and facilitates communications through the assignment of:
a. Public keys
b. Session keys
c. Passwords
d. Tokens

Check back soon!

Problem 13

In a relational database, data access security is provided through:
a. Domain
b. Views
c. Pointers
d. Attributes

Check back soon!

Problem 14

In a biometric system, the time that it takes to register with the system by providing samples of a biometric characteristic is called:
a. Setup time
b. Login time
c. Enrollment time
d. Throughput time

Check back soon!

Problem 15

Which one of the following statements is TRUE concerning Terminal Access Controller Access Control System (TACACS) and TACACS+?
a. TACACS supports prompting for a password change.
b. TACACS+ employs tokens for two-factor, dynamic password authentication.
c. TACACS+ employs a user ID and static password.
d. TACACS employs tokens for two-factor, dynamic password authentication.

Check back soon!

Problem 16

An attack that can be perpetrated against call forwarding is which of the following types of access controls?
a. Time stamping
b. Digital certificate
c. Timeout
d. Callback

Check back soon!

Problem 17

In biometrics, a "one-to-one" search to verify an individual's claim of an identity is called:
a. Authentication
b. Audit trail review
c. Accountability
d. Aggregation

Check back soon!

Problem 18

Which one of the following is a goal of integrity?
a. Accountability of responsible individuals
b. Prevention of the modification of information by unauthorized users
c. Prevention of the unauthorized disclosure of information
d. Preservation of internal and external consistency

Check back soon!

Problem 19

A security kernel is:
a. An abstract machine that mediates all accesses of subjects to objects
b. The hardware, firmware, and software elements of a trusted computing base that implement the reference monitor concept
c. The protected part of the operating system
d. A means of controlling the administration of a database

Check back soon!

Problem 20

Users who possess the ability to bypass most access controls are:
a. Anonymous users
b. Privileged users
c. Guest users
d. Trusted users

Check back soon!
05:51

Problem 21

In finger scan technology:
a. The full fingerprint is stored.
b. Features extracted from the fingerprint are stored.
c. More storage is required than in fingerprint technology.
d. The technology is applicable to large, one-to-many database searches.

Norma Kimmel
Norma Kimmel
Numerade Educator

Problem 22

Mandatory access control uses which of the following pairs to authorize access to information?
a. Roles and identity
b. Clearances and roles
c. Classification and clearances
d. Identity and roles

Check back soon!

Problem 23

An example of two-factor authentication is:
a. A password and an ID
b. An ID and a PIN
c. A PIN and an ATM card
d. A fingerprint

Check back soon!

Problem 24

The Crossover Error Rate (CER) refers to which one of the following technologies?
a. Employee history
b. Databases
c. Cryptography
d. Biometrics

Check back soon!

Problem 25

Biometrics is used for authentication in the logical controls and for identification in the:
a. Detective controls
b. Physical controls
c. Preventive controls
d. Corrective controls

Check back soon!

Problem 26

Which of the following is NOT an assumption of the basic Kerberos paradigm?
a. Client computers are not secured and are easily accessible.
b. Cabling is not secure.
c. Messages are not secure from interception.
d. Specific servers and locations cannot be secured.

Check back soon!

Problem 27

Logon notification, detection of user inactivity, and multiple logon control are examples of what level of access control?
a. System level
b. Account level
c. Data level
d. Session level

Check back soon!

Problem 28

A dynamic password is one that:
a. Is the same for each logon
b. Is a long word or phrase that is converted by the system to a password
c. Changes at each logon
d. Is unverifiable

Check back soon!

Problem 29

Procedures that ensure that the access control mechanisms correctly implement the security policy for the entire life cycle of an information system are known as:
a. Accountability procedures
b. Authentication procedures
c. Assurance procedures
d. Trustworthy procedures

Check back soon!

Problem 30

CHAP is:
a. A protocol for establishing the authenticity of remote users
b. A protocol for establishing the authenticity of palm prints
c. A protocol for establishing the authenticity of Kerberos exchanges
d. A protocol for establishing TCP/IP connections

Check back soon!