Management questions with verified answers
a central authority determines what subjects can have access to certain objects
based on the organizational security policy is called Ans✓✓✓ non-discretionary
access control
a central authority determines what subjects can have access to certain objects
based on the organizational security policy is called Ans✓✓✓ non-discretionary
access control
A confidential number used as an authentication factor to verify a user's identity
is called a Ans✓✓✓ PIN
A database view is the results of which of the following operations? Ans✓✓✓
Join, Project, and Select.
A host-based IDS is resident on which of the following? Ans✓✓✓ On each of the
critical hosts
A network-based vulnerability assessment is a type of test also referred to as:
Ans✓✓✓ An active vulnerability assessment.
A potential problem related to the physical installation of the Iris Scanner in
regards to the usage of the iris pattern within a biometric system is Ans✓✓✓ The
optical unit must be positioned so that the sun does not shine into the aperture
A smart Card that has two chips with the Capability of utilizing both Contact and
Contactless formats is called: Ans✓✓✓ Hybrid Cards
,Access control is the collection of mechanisms that permits managers of a system
to exercise a directing or
restraining influence over the behavior, use, and content of a system. It does not
permit management to: Ans✓✓✓ specify how to restrain hackers
Access Control techniques do not include which of the following choices?
Ans✓✓✓ Relevant Access Controls
an access control policy for a bank teller is an example of the implementation of
Ans✓✓✓ Role-based policies
An access system that grants users only those rights necessary for them to
perform their work is operating on
which security principle? Ans✓✓✓ Least Privilege
An attack initiated by an entity that is authorized to access system resources but
uses them in a way not
approved by those who granted the authorization is known as a(n): Ans✓✓✓
inside attack.
An employee ensures all cables are shielded, builds concrete walls that extend
from the true floor to the true
ceiling and installs a white noise generator. What attack is the employee trying to
protect against? Ans✓✓✓ Emanation Attacks
, An Intrusion Detection System (IDS) is what type of control? Ans✓✓✓ A
detective control.
Another type of access control is lattice-based access control. In this type of
control a lattice model is applied.
How is this type of access control concept applied? Ans✓✓✓ The pair of
elements is the subject and object, and the subject has an upper bound equal or
higher than the
upper bound of the object being accessed.
Attributes that characterize an attack are stored for reference using which of the
following Intrusion Detection
System (IDS)? Ans✓✓✓ signature-based IDS
Business Impact Analysis (BIA) is about Ans✓✓✓ Supporting the mission of the
organization
Considerations of privacy and physical comfort using the system are important
elements for Ans✓✓✓ acceptability of biometrics systems
Controlling access to information systems and associated networks is necessary
for the preservation of Ans✓✓✓ CIA
Controls are implemented to: Ans✓✓✓ mitigate risk and reduce the potential for
loss