• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 34 pages
Exam (elaborations)

WGU D317 IT APPLICATIONS 2026 QUESTIONS AND ANSWERS SURE A.pdf

Document preview thumbnail
Preview 4 out of 34 pages

WGU D317 IT APPLICATIONS 2026 QUESTIONS AND ANSWERS SURE A.pdf

Content preview

WGU D317 IT APPLICATIONS 2026 QUESTIONS
AND ANSWERS SURE A+
✔✔AAA triad - ✔✔Authentication means that everything using the system is identified
by an account and that an account can only be operated by someone who can supply
the correct credentials

Authorization means access to resources is allowed only to accounts with defined
permissions. Each resource has an access control list specifying what users can do.
Resources often have different access levels; for example, being able to read a file or
being able to read and edit it.

Accounting means logging when and by whom a resource was accessed

✔✔Access Control List (ACL) - ✔✔A clearly defined list of permissions that specifies
what actions an authenticated user may perform on a shared resource.

✔✔Access Control Entry (ACE) - ✔✔Within an ACL, each ACE identifies a subject and
the permissions it has for the resource. A subject could be a human user, computer, or
a software service. Subjects can be identified in several ways.

✔✔Implicit Deny - ✔✔Basic principle of security stating that unless something has
explicitly been granted access, it should be denied access.

,This principle can be seen clearly in firewall policies as firewall filters access requests
using a set of rules. The rules are processed in order from top to bottom. If a request
does not fit any of the rules, it is handled by the last (default) rule, which is to refuse the
request

✔✔Least Privilege - ✔✔Basic principle of security stating that something should be
allocated the minimum necessary rights, privileges, or information to perform its role.
This can be complex to apply in practice.
Designing a permissions systems that respects the principle of least privilege while not
generating too many support requests from users is a challenging task

✔✔Local Account - ✔✔Defined on that computer only.
A local user account is stored in a database known as the Security Account Manager
(SAM), which is part of the HKEY_LOCAL_MACHINE registry. Each machine maintains
its own SAM and set of SIDs for accounts. Consequently, a local account cannot be
used to log on to a different computer or access a file over the network

✔✔Security Group - ✔✔Access control feature that allows permissions to be allocated
to multiple users more efficiently
A collection of user accounts.
Used when assigning permissions and rights, as it is more efficient to assign
permissions to a group than to assign them individually to each user.

✔✔Administrators Group - ✔✔Can perform all management tasks and generally has a
very high access to all files and other objects int he system. The local or Microsoft user
created during setup is automatically added to this group.
It is more secure to restrict membership of the Administrators group as tightly as
possible

✔✔Standard Account - ✔✔A member of the Users group.
Generally only able to configure settings for its profile. However, it can also shut down
the computer, run desktop applications, instal and run store apps, and use printers.
Additional accounts should be set up as standard users unless there is a compelling
reason to add another administrative account.

✔✔Guest Group - ✔✔Only present for legacy reasons. Has the same default
permissions and rights as the User group.
Disabled by default.
Microsoft ended support for using the guest account login to Windows in a feature
update.
Guest account is only used to implement file sharing without passwords

✔✔Power Users - ✔✔Present to support legacy applications.
Historically, this group was intended to have intermediate permissions between
administrators and users. However, this approach created vulnerabilities that allowed

,accounts to escalate to the administrators group. In Windows 10/11 this group has the
same permissions as the standard Users group.

✔✔net user Commands in the administrative command prompt. - ✔✔Add a new user
account & force the user to choose a new password at first login:
net user dmarting Pa$$w0rd /add
/fullname:"David Martin"
/logonpasswordchg:yes

Disable the dmartin account:
net user dmartin /active:no

Show properties of the dmartin account:
net user dmartin

Add the dmartina ccount to the Administrators local group:
net localgroup Administrators dmartin /add

✔✔Multifactor Authentication (MFA) - ✔✔The user must submit at least two different
types of credentials. There are several standard multifactor technologies

✔✔2-step Verification - ✔✔A means of using a soft token to check that a sign-in request
is authentic
It works on the following lines:
1. The user registers a trusted contact method with the app. This could be an email
account or phone number, for instance
2. The user logs on to the app using a password or biometric recognition
3. If the app detects a new device or that the user is signing on from a different locations
or is just configured by policy to require 2-step verification in all instances, it generates a
soft token & send this to a registered email or phone number. The code can be
delivered by email, sms text, or as an automated voice call
4. The user must then input the soft token code within a given time frame to be granted
access

✔✔Soft Token - ✔✔Either an additional code to use for 2-step verification, such as a
one-time password, or authorization data that can be presented as evidence of
authentication in an SSO system

✔✔Authenticator Application - ✔✔Software that allows a smartphone to operate as a
second authentication factor or as a trusted channel for 2-step verification
This works as follows:
1. Authenticator app is installed to a trusted device, such as the users smartphone.
Smartphone must be protected by its own authentication system, such as screen lock
opened by fingerprint
2. Service or network that the user needs to authenticate with is registered with the
authenticator app, typically by scanning a quick QR code and then completing some

, validation checks. Registration uses encryption keys to establish a trust relationship
between the service and the authenticator app.
3. When the user tries to sign in, the service or network generates a prompt on the
authenticator. User must unlock his or her device to authorize the sign-in request.
4. Authenticator then either displays a soft token for the user to input or directly
communicates to the service or network that the user supplied their credential
5. The service grants the user access

✔✔Hard Token - ✔✔Works in the same sort of way as an authenticator app but is
implemented as firmware in a smart card or USB thumb drive rather than running on a
smartphone.
Hard token is first registered with the service or network. When the user needs to
authenticate, they connect the token and authorizes it via a password, PIN, fingerprint
reader, or voice recognition.
The token transmits its credential to the service, and the service grants the user access.
These devices are typically compliant with Fast Identity Online (FIDO) version 2
standards

✔✔Kerberos - ✔✔Single sign-on authentication and authorization service that is based
on a time-sensitive, ticket-granting system

✔✔Windows Hello - ✔✔Feature that supports passwordless sign-in for Windows
A subsystem that allows the user to configure an alternative means of authenticating.
Depending on hardware support, the following options are available:
PIN
Fingerprint
Facial recognition
Security Key

✔✔Trusted Platform Module (TPM) - ✔✔Feature of the CPU or chipset and encryption
to ensure that the PIN does not have to be stored on the device itself.
Specification for secure hardware-based storage of encryption keys, hashed
passwords, and other user- and platform-identification information.

✔✔Single Sign-On (SSO) - ✔✔Authentication technology that enables a user to
authenticate once and receive authorizations for multiple services
DisadvantageL a compromised account also compromises multiple services
The use of passwords in SSO systems has proven extremely vulnerable to attacks

✔✔Domain - ✔✔Group of hosts that is within the same namespace and administered by
the same authority

✔✔Domain Controller (DC) - ✔✔Stores a database of network information called Active
Directory
Responsible for providing an authentication service to users as they attempt to sign in.

Document information

Uploaded on
July 12, 2026
Number of pages
34
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BOARDWALKer
3.4
(19)
Sold
157
Followers
7
Items
26502
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions