WGU C845 VUN1 TASK 3 ACTUAL QUESTIONS
AND CORRECT ANSWERS
◉ A new member at a 24 hour gym that uses fingerprints to gain
access after hours is surprised to find out that he is registering as a
different member. What type of biometric factor error occurred?
Answer: Since he was accepted as a different member this was a
Type 2 (false positive) error. If he was not accepted and the door
remained locked it would have been a Type 1 (false negative) error.
◉ You are tasked with adjusting your organizations password
requirements to make them align with best practices from NIST.
What should you set password expiration to?
Answer: NIST Special Publication 800-63b suggests that
organizations should not impose password expiration requirements
on end users
◉ What access control scheme labels subjects and objects and
allows subjects to access objects when labels match?
Answer: Mandatory Access Control (MAC)
◉ Mandatory Access Control is based on what type of model?
Answer: Lattice Based
,◉ You need to create a trust relationship between your company
and a vendor. You need to implement the system so that it will allow
users from the vendor's organization to access your accounts
payable system using the accounts created for them by the vendor.
What type of authentication do you need to implement?
Answer: This type of authentication, where one domain trusts users
from another domain, is called federation.
◉ Users change job positions quite often at your new company.
Which type of access control would make it easier to allow
administrators to adjust permissions when these changes occur?
A. Role-Based Access Control
B. Mandatory Access Control
C. Discretionary Access Control
D. Rule-Based Access Control
Answer: A Role-Based Access Control would assign permission to
roles and then the administrator would simply adjust the role of the
user when he or she changes jobs
◉ Which of the following authenticators is appropriate to use by
itself rather than in combination with other biometric factors?
A. Voice pattern recognition
B. Hand geometry
C. Palm scans
,D. Heart/pulse patterns
Answer: C. Palm scans compare the vein patterns in the palm to a
database to authenticate a user.
◉ As part of hiring a new employee, Sven's identity management
team creates a new user object and ensures that the user object is
available in the directories and systems where it is needed. What is
this process called?
Answer: Provisioning includes the creation, maintenance, and
removal of user objects from applications, systems, and directories.
◉ The Linux filesystem allows the owners of objects to determine
the access rights that subjects have to them. What type of access
control does Linux use?
Answer: Discretionary Access Control
◉ Mary's organization handles very sensitive governmental agency
information. They need to implement an access control system that
allows administrators to set access rights but does not allow the
delegation of those rights to other users. What is the best type of
access control design for Mary's organization?
Answer: Mandatory Access Control (MAC) systems allow an
administrator to configure access permissions but do not allow
users to delegate permission to others.
, ◉ What term is used to describe the default set of privileges
assigned to a user when a new account is created?
A. Aggregation
B. Transitivity
C. Baseline
D. Entitlement
Answer: D. Entitlement refers to the privileges granted to useres
when an account is first provisioned.
◉ Steve is the risk manager for a company on the east coast of the
United States. He recently undertook a replacement cost analysis
and determined that rebuilding and reconfiguring the data center
would cost $20 million. Steve consulted with hurricane experts, data
center specialists, and structural engineers and they determined
that a typical CAT 3 hurricane that successfully hits the east coast
would cause approximately $5 million in damages. The
meteorologists determined that Steve's facility lies in an area where
they are likely to experience a CAT 3 hurricane once every 10 years.
Based upon the information in this scenario, what is the exposure
factor for the effect of a CAT 3 hurricane on Steve's data center?
Answer: The exposure factor is the percentage of the facility that
risk managers expect will be damaged if a risk materializes. It is
calculated by dividing the amount of damage by the asset value. In
this case, that is $5 million in damage divided by the $20 million
facility value, or 25 percent.
AND CORRECT ANSWERS
◉ A new member at a 24 hour gym that uses fingerprints to gain
access after hours is surprised to find out that he is registering as a
different member. What type of biometric factor error occurred?
Answer: Since he was accepted as a different member this was a
Type 2 (false positive) error. If he was not accepted and the door
remained locked it would have been a Type 1 (false negative) error.
◉ You are tasked with adjusting your organizations password
requirements to make them align with best practices from NIST.
What should you set password expiration to?
Answer: NIST Special Publication 800-63b suggests that
organizations should not impose password expiration requirements
on end users
◉ What access control scheme labels subjects and objects and
allows subjects to access objects when labels match?
Answer: Mandatory Access Control (MAC)
◉ Mandatory Access Control is based on what type of model?
Answer: Lattice Based
,◉ You need to create a trust relationship between your company
and a vendor. You need to implement the system so that it will allow
users from the vendor's organization to access your accounts
payable system using the accounts created for them by the vendor.
What type of authentication do you need to implement?
Answer: This type of authentication, where one domain trusts users
from another domain, is called federation.
◉ Users change job positions quite often at your new company.
Which type of access control would make it easier to allow
administrators to adjust permissions when these changes occur?
A. Role-Based Access Control
B. Mandatory Access Control
C. Discretionary Access Control
D. Rule-Based Access Control
Answer: A Role-Based Access Control would assign permission to
roles and then the administrator would simply adjust the role of the
user when he or she changes jobs
◉ Which of the following authenticators is appropriate to use by
itself rather than in combination with other biometric factors?
A. Voice pattern recognition
B. Hand geometry
C. Palm scans
,D. Heart/pulse patterns
Answer: C. Palm scans compare the vein patterns in the palm to a
database to authenticate a user.
◉ As part of hiring a new employee, Sven's identity management
team creates a new user object and ensures that the user object is
available in the directories and systems where it is needed. What is
this process called?
Answer: Provisioning includes the creation, maintenance, and
removal of user objects from applications, systems, and directories.
◉ The Linux filesystem allows the owners of objects to determine
the access rights that subjects have to them. What type of access
control does Linux use?
Answer: Discretionary Access Control
◉ Mary's organization handles very sensitive governmental agency
information. They need to implement an access control system that
allows administrators to set access rights but does not allow the
delegation of those rights to other users. What is the best type of
access control design for Mary's organization?
Answer: Mandatory Access Control (MAC) systems allow an
administrator to configure access permissions but do not allow
users to delegate permission to others.
, ◉ What term is used to describe the default set of privileges
assigned to a user when a new account is created?
A. Aggregation
B. Transitivity
C. Baseline
D. Entitlement
Answer: D. Entitlement refers to the privileges granted to useres
when an account is first provisioned.
◉ Steve is the risk manager for a company on the east coast of the
United States. He recently undertook a replacement cost analysis
and determined that rebuilding and reconfiguring the data center
would cost $20 million. Steve consulted with hurricane experts, data
center specialists, and structural engineers and they determined
that a typical CAT 3 hurricane that successfully hits the east coast
would cause approximately $5 million in damages. The
meteorologists determined that Steve's facility lies in an area where
they are likely to experience a CAT 3 hurricane once every 10 years.
Based upon the information in this scenario, what is the exposure
factor for the effect of a CAT 3 hurricane on Steve's data center?
Answer: The exposure factor is the percentage of the facility that
risk managers expect will be damaged if a risk materializes. It is
calculated by dividing the amount of damage by the asset value. In
this case, that is $5 million in damage divided by the $20 million
facility value, or 25 percent.