CISEC ACTUAL EXAM FINAL
COMPREHENSIVE ASSESSMENT TEST
PAPER QUESTIONS AND SOLUTIONS
⩥ Mandatory Access Control (MAC).
Answer: Permissions to objects are managed centrally by an
administrator. Is an access policy determined by the system, rather than
by the owner. Organizations use this in multilevel systems that process
highly sensitive data such as classified govt or military.
Examples: 1) Rule-based, 2) Lattice Model
⩥ Discretionary Access Control (DAC).
Answer: Is an access policy determined by the owner of a file (or other
resource). The owner decides who's allowed access to a file and what
privileges they have.
⩥ Role Based Access Control (RBAC).
Answer: A method of implementing discretionary access controls in
which access decisions are based on group membership, according to
organization or functional roles.
⩥ LDAP - Lightweight Directory Access Protocol.
,Answer: An Internet Protocol (IP) and data storage model that supports
authentication and directory functions. It is a remote access
authentication protocol. Vendors = Microsoft Active Directory, CA
eTrust Directory, Apache Directory Server, Novell eDirectory, IBM
SecureWay and Tivoli Directory Server, Sun Directlry Server.
OpenLDAP and tinyldap open source versions.
⩥ User Account.
Answer: Allows a user to authenticate to system services and be granted
authorization to access them; however, authentication does not imply
authorization.
⩥ Service Account.
Answer: Is an account that a service on your computer uses to run under
and access resources. This should not be a user's personal account. Can
also be an account that is used for a scheduled task (e.g., batch job
account) or an account that is used in a script that is run outside of a
specific user's context. (Ref GIAC White Paper)
⩥ Default Account.
Answer: System login account predefined in a manufactured system to
permit initial access when system is first put into service. (pciscanner)
⩥ Guest Account.
,Answer: For users who don't have a permanent account on your
computer or domain. It allows people to use your computer without
having access to personal files. Per MSFT cannot install software or
hardware, change settings, or create a password. (MSFT)
⩥ Account expiration.
Answer: A time limit that is applied to the life of an account, so that it
can be used only for a predetermined period of time. (MSFT)
⩥ Access Control List (ACL).
Answer: List of subjects (including groups, machines, processes*) that
are authorized to access a particular object. Typically, the types of access
are read, write, execute, append, modify, delete and create. (Harris)
(*NIST)
⩥ Access Reconciliation.
Answer: The action of making accounts consistent. A process used to
compare two sets of records to ensure the data are in agreement and are
accurate.
⩥ Configuration Control.
Answer: Process of controlling modifications to hardware, firmware,
software and documentation to protect the information system against
improper modification prior to, during, and after system implementation.
(NIST)
, ⩥ Baseline Configuration.
Answer: A set of specifications for a system that has been formally
reviewed and agreed on at a given point in time, and which can be
changed only through change control procedures. Used as a basis for
future builds, releases, and/or changes. (NIST)
⩥ Baseline.
Answer: A process that identifies a consistent basis for an organization's
security architecture, taking into account system-specific parameters,
such as different operating systems. (Dummies)
A minimum level of security necessary throughout the organization
(CISA)
⩥ Configuration Auditing.
Answer: Check that:
- Change was recorded correctly and work matched the Request for
Change (RFC)
- Change had appropriate risk level
- Configuration items updated appropriately
- Documentation updated
(CISCO)
COMPREHENSIVE ASSESSMENT TEST
PAPER QUESTIONS AND SOLUTIONS
⩥ Mandatory Access Control (MAC).
Answer: Permissions to objects are managed centrally by an
administrator. Is an access policy determined by the system, rather than
by the owner. Organizations use this in multilevel systems that process
highly sensitive data such as classified govt or military.
Examples: 1) Rule-based, 2) Lattice Model
⩥ Discretionary Access Control (DAC).
Answer: Is an access policy determined by the owner of a file (or other
resource). The owner decides who's allowed access to a file and what
privileges they have.
⩥ Role Based Access Control (RBAC).
Answer: A method of implementing discretionary access controls in
which access decisions are based on group membership, according to
organization or functional roles.
⩥ LDAP - Lightweight Directory Access Protocol.
,Answer: An Internet Protocol (IP) and data storage model that supports
authentication and directory functions. It is a remote access
authentication protocol. Vendors = Microsoft Active Directory, CA
eTrust Directory, Apache Directory Server, Novell eDirectory, IBM
SecureWay and Tivoli Directory Server, Sun Directlry Server.
OpenLDAP and tinyldap open source versions.
⩥ User Account.
Answer: Allows a user to authenticate to system services and be granted
authorization to access them; however, authentication does not imply
authorization.
⩥ Service Account.
Answer: Is an account that a service on your computer uses to run under
and access resources. This should not be a user's personal account. Can
also be an account that is used for a scheduled task (e.g., batch job
account) or an account that is used in a script that is run outside of a
specific user's context. (Ref GIAC White Paper)
⩥ Default Account.
Answer: System login account predefined in a manufactured system to
permit initial access when system is first put into service. (pciscanner)
⩥ Guest Account.
,Answer: For users who don't have a permanent account on your
computer or domain. It allows people to use your computer without
having access to personal files. Per MSFT cannot install software or
hardware, change settings, or create a password. (MSFT)
⩥ Account expiration.
Answer: A time limit that is applied to the life of an account, so that it
can be used only for a predetermined period of time. (MSFT)
⩥ Access Control List (ACL).
Answer: List of subjects (including groups, machines, processes*) that
are authorized to access a particular object. Typically, the types of access
are read, write, execute, append, modify, delete and create. (Harris)
(*NIST)
⩥ Access Reconciliation.
Answer: The action of making accounts consistent. A process used to
compare two sets of records to ensure the data are in agreement and are
accurate.
⩥ Configuration Control.
Answer: Process of controlling modifications to hardware, firmware,
software and documentation to protect the information system against
improper modification prior to, during, and after system implementation.
(NIST)
, ⩥ Baseline Configuration.
Answer: A set of specifications for a system that has been formally
reviewed and agreed on at a given point in time, and which can be
changed only through change control procedures. Used as a basis for
future builds, releases, and/or changes. (NIST)
⩥ Baseline.
Answer: A process that identifies a consistent basis for an organization's
security architecture, taking into account system-specific parameters,
such as different operating systems. (Dummies)
A minimum level of security necessary throughout the organization
(CISA)
⩥ Configuration Auditing.
Answer: Check that:
- Change was recorded correctly and work matched the Request for
Change (RFC)
- Change had appropriate risk level
- Configuration items updated appropriately
- Documentation updated
(CISCO)