CISSP DOMAIN 1 EXAM QUESTIONS
WITH 100% CORRECT ANSWERS
Type of controls used to protect access to the physical facilities housing information
systems. - Answer- Physical controls
States that the subjects of an access control system should have the minimum set of
access permissions necessary to complete their assigned job functions. - Answer-
Principle of least privilege
The ability to perform critical system functions should be divided among different
individuals to minimize the risk of collusion. - Answer- Separation of duties
Users should only have access to information that they have a need to know to perform
their assigned responsibilities. - Answer- Need to know
Users gain different access permissions as they move from position to position in an
organization but old permissions are not revoked. - Answer- Privilege creep
Authorization of the subjects access to an object depends on labels which indicate a
subjects clearance and the classification or sensitivity of the related object - Answer-
Mandatory access control (MAC)
Access control type where the subject has authority to specify what objects can be
accessible. - Answer- Discretionary access control (DAC)
Access control type where the Administrator determines which subjects can have
access to certain objects based on an organizations security policy. - Answer- Non-
discretionary access control (NDAC) also known as role based access control (RBAC)
Access control type where the administrator specifies upper and lower bounds of the
authority for each subject and uses those boundaries to determine access permissions.
- Answer- Lattice based access control (LBAC)
Four types of access control systems. - Answer- MAC, DAC, NDAC (RBAC), LBAC
A central authentication and/or authorization point for an enterprise. - Answer-
Centralized access control system
A series of diverse access control systems at different points throughout the enterprise.
- Answer- Decentralized access control systems
, Technology that enables centralized authentication. - Answer- Single sign on (SSO)
Software used on a network to establish a users identity. - Answer- Kerberos
Three components of kerberos - Answer- Key distribution center (KDC), Authentication
service (AS), Ticket granting service (TGS)
A public key based alternative to kerberos - Answer- SESAME
Three authentication factors. - Answer- Something you know, something you have,
something you are
Using at least two authentication factors. - Answer- Two-factor authentication
The most commonly implemented authentication technique. - Answer- Passwords
Four different kinds of tokens - Answer- Static password, synchronous dynamic
password, asynchronous dynamic password, challenge-response token
Token type where the owner authenticates himself to the token and the token
authenticates the owner to the system. - Answer- Static password token
Token type where the token generates a new unique password at fixed time intervals,
user enters a unique password and user name into the system, and the system
confirms that the password and user name are correct and were entered during the
allowed time interval. - Answer- Synchronous dynamic password token
User makes a claim as to his or her identity. - Answer- Identification
User proves his or her identity using one or more mechanisms. - Answer- Authentication
System makes decisions about what resources the user is allowed to access and the
manner in which they may be manipulated. - Answer- Authorization
System keeps an accurate audit trail of the users activity. - Answer- Accounting
Entities that may be assigned permissions. - Answer- Subjects
Types of resources that subjects may access. - Answer- Objects
Relationships between subjects and the objects they may access. - Answer- Access
permissions
Contains access control entities (ACEs) that correspond to access permissions. -
Answer- Access control list (ACL)
WITH 100% CORRECT ANSWERS
Type of controls used to protect access to the physical facilities housing information
systems. - Answer- Physical controls
States that the subjects of an access control system should have the minimum set of
access permissions necessary to complete their assigned job functions. - Answer-
Principle of least privilege
The ability to perform critical system functions should be divided among different
individuals to minimize the risk of collusion. - Answer- Separation of duties
Users should only have access to information that they have a need to know to perform
their assigned responsibilities. - Answer- Need to know
Users gain different access permissions as they move from position to position in an
organization but old permissions are not revoked. - Answer- Privilege creep
Authorization of the subjects access to an object depends on labels which indicate a
subjects clearance and the classification or sensitivity of the related object - Answer-
Mandatory access control (MAC)
Access control type where the subject has authority to specify what objects can be
accessible. - Answer- Discretionary access control (DAC)
Access control type where the Administrator determines which subjects can have
access to certain objects based on an organizations security policy. - Answer- Non-
discretionary access control (NDAC) also known as role based access control (RBAC)
Access control type where the administrator specifies upper and lower bounds of the
authority for each subject and uses those boundaries to determine access permissions.
- Answer- Lattice based access control (LBAC)
Four types of access control systems. - Answer- MAC, DAC, NDAC (RBAC), LBAC
A central authentication and/or authorization point for an enterprise. - Answer-
Centralized access control system
A series of diverse access control systems at different points throughout the enterprise.
- Answer- Decentralized access control systems
, Technology that enables centralized authentication. - Answer- Single sign on (SSO)
Software used on a network to establish a users identity. - Answer- Kerberos
Three components of kerberos - Answer- Key distribution center (KDC), Authentication
service (AS), Ticket granting service (TGS)
A public key based alternative to kerberos - Answer- SESAME
Three authentication factors. - Answer- Something you know, something you have,
something you are
Using at least two authentication factors. - Answer- Two-factor authentication
The most commonly implemented authentication technique. - Answer- Passwords
Four different kinds of tokens - Answer- Static password, synchronous dynamic
password, asynchronous dynamic password, challenge-response token
Token type where the owner authenticates himself to the token and the token
authenticates the owner to the system. - Answer- Static password token
Token type where the token generates a new unique password at fixed time intervals,
user enters a unique password and user name into the system, and the system
confirms that the password and user name are correct and were entered during the
allowed time interval. - Answer- Synchronous dynamic password token
User makes a claim as to his or her identity. - Answer- Identification
User proves his or her identity using one or more mechanisms. - Answer- Authentication
System makes decisions about what resources the user is allowed to access and the
manner in which they may be manipulated. - Answer- Authorization
System keeps an accurate audit trail of the users activity. - Answer- Accounting
Entities that may be assigned permissions. - Answer- Subjects
Types of resources that subjects may access. - Answer- Objects
Relationships between subjects and the objects they may access. - Answer- Access
permissions
Contains access control entities (ACEs) that correspond to access permissions. -
Answer- Access control list (ACL)