• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 12 pages
Exam (elaborations)

ISSC 451 Week 3 Quiz – Information Systems Security Study Guide and Practice Questions (2026/2027)

Document preview thumbnail
Preview 2 out of 12 pages

This document contains study material and practice questions for the ISSC 451 Week 3 Quiz, covering core concepts in information systems security and cybersecurity. Topics include security principles, threat landscapes, risk management, network security fundamentals, access control, authentication, security models, vulnerability assessment, and foundational defensive security practices. It is designed to help students prepare for weekly quizzes and strengthen their understanding of essential information security concepts. The material includes review questions and quiz-focused content aligned with ISSC 451 course learning objectives and commonly assessed cybersecurity competencies. It is useful for self-study, quiz preparation, and reinforcing the technical knowledge, critical thinking, and analytical skills required to secure information systems and organizational assets.

Content preview

ISSC 451 Week 3 Quiz — 2026/2027
Curriculum
Total Questions: 25 | Time Recommended: 45 minutes

SECTION A: MULTIPLE CHOICE (Questions 1–20)

Q1: In the Discretionary Access Control (DAC) model, who is ultimately
responsible for determining access rights to a resource?

A) The system administrator
B) The resource owner

C) The security officer

D) The operating system kernel

Answer: B

Explanation: In DAC, the owner of a resource (such as a file creator) has the
discretion to grant or revoke access permissions to other users, typically
implemented through Access Control Lists (ACLs).

Q2: Which access control model uses security labels and is primarily designed to
enforce confidentiality by preventing users from reading data at a higher
classification level?
A) RBAC

B) MAC (Mandatory Access Control)

C) ABAC
D) DAC

Answer: B

Explanation: MAC uses system-enforced security labels (e.g., Top Secret, Secret,
Confidential) and follows the Bell-LaPadula model's "no read up, no write down"
principle to protect confidentiality.

Q3: In the Bell-LaPadula model, the Simple Security Property (ss-property) states
that a subject cannot:
A) Read data at a lower classification level

, B) Read data at a higher classification level

C) Write data to a higher classification level

D) Execute programs at any classification level

Answer: B
Explanation: The ss-property, or "no read up," prevents subjects from reading
objects at a higher security classification, ensuring users cannot access more
sensitive data than their clearance allows.

Q4: A large hospital implements access control where physicians, nurses, and
billing staff each receive permissions based on their job function. This is an
example of:
A) DAC

B) MAC

C) RBAC (Role-Based Access Control)

D) Rule-Based Access Control
Answer: C

Explanation: RBAC assigns permissions based on predefined roles (e.g.,
physician, nurse, billing staff) rather than individual identities, simplifying
administration in large organizations.

Q5: An organization needs to grant access to a sensitive database only during
business hours, from corporate IP addresses, and only on managed devices.
Which access control model best supports these requirements?
A) DAC

B) MAC

C) RBAC
D) ABAC (Attribute-Based Access Control)

Answer: D

Explanation: ABAC evaluates dynamic attributes including user identity, resource
sensitivity, environmental conditions (time, location), and device posture to make
granular, context-aware access decisions.
Q6: A firewall that permits HTTP traffic on port 80 but blocks all other inbound
connections is implementing which type of access control?

Document information

Uploaded on
July 6, 2026
Number of pages
12
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ExamAceStuvia
3.7
(12)
Sold
60
Followers
0
Items
1260
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions