Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 17 pages
Exam (elaborations)

CNIT 270 Exam 1 Questions and Answers

Document preview thumbnail
Preview 3 out of 17 pages

CNIT 270 Exam 1 Questions and Answers

Content preview

CNIT 270 Exam 1



What are the 3 key security concepts of the CIA triad? - Answer-Confidentiality, Integrity, and
Availabiblity



Which concept from the CIA triad preserves authorized restrictions on information access and
disclosure, including means for protecting personal privacy and proprietary information? - Answer-
Confidentiality



Which concept from the CIA triad guards against improper information modification or destruction,
including ensuring information nonrepudiation and authenticity? - Answer-Integrity



Which concept from the CIA triad ensures timely and reliable access to and use of information? -
Answer-Availabiblity



In addition to the CIA triad concepts, what 3 extra concepts does the Parkerian Hexad add? - Answer-
Non-repudiation, Possession/Control, Utility/Usefulness



What are the 3 types of assets? - Answer-Hardware, Software, and Data



What are the 4 types of harm? - Answer-Interception, Interruption, Modification, and Fabrication



What are the 4 ways to prove authentication? - Answer-what you know, what you are, what you have,
where you are

,What are "should do" NIST Guidelines for passwords? - Answer-favor the user, size matters, allow all
UNICODE characters, check against a dictionary of known bad choices



What are "should not do" NIST Guidelines for passwords? - Answer-have composition rules, password
hints, expiration without reason, SMS in two factor authentication, knowledge-based authentication



What is a Smart Card? - Answer-looks like a credit card but contains an entire microprocessor. a way of
authenticating with what you have.



What is access control? - Answer-Technology or procedures that implement a security policy to specify
who or what may have access to each specific system resource and the type of access permitted in each
instance.



What are the 4 types of access control policies? - Answer-Discretionary (DAC), Mandatory (MAC), Role-
based (RBAC), and Attribute-based (ABAC).



What does SetGID do? - Answer-Temporarily uses rights of the file owner/group in addition to real
user's rights when making access control decisions. Enables privileged programs to access
files/resources not generally accessible.



What is a sticky bit? - Answer-When applied to a directory it specifies that only the owner of any file in
the directory can rename, move, or delete that file.



What is a superuser? - Answer-A user that is exempt from usual access control restrictions and has
system-wide access. This account can take ownership and change the permissions of all objects in the
system. "ROOT"



What is Role-based access control? - Answer-Controls based on the roles that users have within the
system and on rules stating what accesses are allowed to users in given roles.

, What is Discretionary access control? - Answer-Controls based on the ID of the requestor.



What is Mandatory access control? - Answer-Controls are based on comparing labels indicating
sensitivity of resources with security clearances. Entities with clearance cannot enabled other entities
access to that resource.



What is Attribute-based access control? - Answer-Controls access based on attributes of the user, the
resource, and current environmental conditions.



What are mutually exclusive roles in terms of RBAC? - Answer-A user can only be assigned to one role in
the set. Any permission can be granted to only one role in the set.



What is cardinality in terms of RBAC? - Answer-Setting a maximum number with respect to roles.



What are prerequisite roles in terms of RBAC? - Answer-Dictates that a user can only be assigned to a
particular role if it is already assigned to some other specified role.



What are 4 methods of procedural access control? - Answer-1) Separation of duties

2) Job rotation

3) Mandatory vacations

4) Principle of least privilege



What is separation of duties in terms of procedural access control? - Answer-If a fraudulent process is
going to be put into action, it should be divided between two or more individuals. No single person
should be able to carry out certain processes unilaterally.

Document information

Uploaded on
June 23, 2025
Number of pages
17
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$19.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Zanaya
4.5
(12)
Sold
77
Followers
29
Items
10176
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions