Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 64 pages
Exam (elaborations)

SANS GICSP UPDATE LATEST EXAM | MOST TESTED QUESTIONS AND VERIFIED ANSWERS GRADED A+ WITH RATIONALES

Document preview thumbnail
Preview 4 out of 64 pages

SANS GICSP UPDATE LATEST EXAM | MOST TESTED QUESTIONS AND VERIFIED ANSWERS GRADED A+ WITH RATIONALES

Content preview

ESTUDY



SANS GICSP UPDATE LATEST EXAM | MOST TESTED
QUESTIONS AND VERIFIED ANSWERS GRADED A+
WITH RATIONALES
1. Which access control model focuses on the flow of information and non-interference?
a) Bell-LaPadula
b) Biba
c) Information Flow and Non-Interference
d) Clark-Wilson
Rationale: Information Flow and Non-Interference models focus on controlling how information
flows within a system and ensuring that actions at one level do not interfere with another.

2. Which model is used to enforce confidentiality in stored information?
a) Bell-LaPadula
b) Biba
c) Clark-Wilson
d) Take-Grant
Rationale: The Bell-LaPadula model is designed to enforce confidentiality by restricting access
based on security levels.

3. What is the primary focus of the Biba Integrity Model?
a) Confidentiality
b) Integrity
c) Availability
d) Non-repudiation
Rationale: The Biba Integrity Model ensures that data integrity is maintained by preventing
unauthorized modification of data.

4. Which access control model allows the owner of a file to determine access permissions?
a) Mandatory Access Control (MAC)
b) Discretionary Access Control (DAC)
c) Role-Based Access Control (RBAC)
d) Rule-Based Access Control
Rationale: DAC allows the owner of a file or resource to decide who can access it and what
permissions they have.

5. What is the primary characteristic of Mandatory Access Control (MAC)?
a) The owner determines access permissions
b) Permissions are managed centrally by an administrator
c) Access is based on group membership

,ESTUDY


d) Access is determined by user roles
Rationale: MAC is centrally managed by an administrator and is often used in systems handling
highly sensitive data.

6. Which of the following is an example of Mandatory Access Control (MAC)?
a) Role-Based Access Control
b) Lattice Model
c) Discretionary Access Control
d) Rule-Based Access Control
Rationale: The Lattice Model is an example of MAC, which uses a mathematical structure to
define access levels.

7. What is the main purpose of Role-Based Access Control (RBAC)?
a) To allow owners to set permissions
b) To base access decisions on group membership and organizational roles
c) To enforce confidentiality through security levels
d) To ensure data integrity
Rationale: RBAC assigns permissions based on roles within an organization, simplifying access
management.

8. Which protocol supports authentication and directory functions in a network?
a) HTTP
b) LDAP (Lightweight Directory Access Protocol)
c) FTP
d) SNMP
Rationale: LDAP is used for accessing and managing directory information services, such as user
authentication.

9. What is the purpose of a user account?
a) To manage system resources
b) To allow a user to authenticate and access system services
c) To provide temporary access to guests
d) To run system services
Rationale: A user account enables authentication and authorization for accessing system
services.

10. What is a service account typically used for?
a) To allow users to log in temporarily
b) To run system services or scheduled tasks
c) To provide administrative access
d) To manage guest access
Rationale: Service accounts are used to run system services or scheduled tasks without using a
personal user account.

,ESTUDY


11. What is a default account?
a) An account created by the system administrator
b) A predefined account in a system for initial access
c) An account used for guest access
d) An account used for running services
Rationale: Default accounts are predefined in systems to allow initial access during setup.

12. What is the primary purpose of a guest account?
a) To provide full access to system resources
b) To allow temporary access without granting personal file access
c) To run system services
d) To manage administrative tasks
Rationale: Guest accounts provide limited access for temporary users without allowing access to
personal files.

13. What does account expiration refer to?
a) The time a user logs out of the system
b) A time limit applied to the life of an account
c) The time a service account is deactivated
d) The time a guest account is created
Rationale: Account expiration sets a time limit for how long an account can be used.

14. What is an Access Control List (ACL)?
a) A list of system services
b) A list of subjects authorized to access an object
c) A list of user roles
d) A list of default accounts
Rationale: An ACL specifies which subjects (users, groups, etc.) are authorized to access an
object and their permissions.

15. What is the purpose of access reconciliation?
a) To create new user accounts
b) To ensure accounts are consistent and accurate
c) To delete expired accounts
d) To manage service accounts
Rationale: Access reconciliation ensures that account records are consistent and accurate across
systems.

16. What is configuration control?
a) The process of creating new system configurations
b) The process of controlling modifications to hardware, software, and documentation
c) The process of managing user accounts
d) The process of setting up guest accounts

, ESTUDY


Rationale: Configuration control ensures that modifications to systems are properly managed
and documented.

17. What is a baseline configuration?
a) A temporary system setup
b) A set of specifications formally reviewed and agreed upon for a system
c) A list of default accounts
d) A configuration used for testing
Rationale: A baseline configuration is a standardized set of specifications used as a reference for
system builds and changes.

18. What is the purpose of configuration auditing?
a) To create new configurations
b) To verify that changes were recorded correctly and configurations are updated
c) To delete outdated configurations
d) To manage user accounts
Rationale: Configuration auditing ensures that changes are properly documented and
configurations are accurate.

19. What is WSUS (Windows Server Update Services) used for?
a) To manage user accounts
b) To provide automatic updates for internal systems
c) To configure baseline settings
d) To audit system configurations
Rationale: WSUS is used to manage and distribute updates within an organization.

20. What is a Man-in-the-Middle (MITM) attack?
a) An attack that floods a network with traffic
b) An attack where an attacker intercepts and modifies messages between two parties
c) An attack that exploits social engineering
d) An attack that spoofs IP addresses
Rationale: In a MITM attack, the attacker intercepts and potentially alters communication
between two parties.

21. What is spoofing in the context of network attacks?
a) Flooding a network with traffic
b) Forging packet information to impersonate a trusted host
c) Exploiting social engineering techniques
d) Intercepting communication between two parties
Rationale: Spoofing involves forging packet information, such as IP addresses, to impersonate a
trusted entity.

22. What is social engineering?
a) A technical attack on network protocols

Document information

Uploaded on
January 15, 2025
Number of pages
64
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
CA$20.80

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Estudyr
3.8
(222)
Sold
1222
Followers
830
Items
11235
Last sold
3 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions