MISY 5325 EXAM 1 ALL QUESTIONS AND ANSWERS
SET A+
✔✔In terms of access control, the active entity that requests access to a resource or
data is referred to as the __________.
object
subject
active
entity - ✔✔subject
✔✔The key concepts of identification include all BUT:
Identities should be unique
Identities should not be location-based
Identities should be nondescriptive
Identities should be securely issued - ✔✔Identities should not be location-based
✔✔There are three categories of indentification factors that include all BUT:
knowledge (something the user knows)
possession (something a user has)
role (something the user does)
inherence or characteristics (something the user is) - ✔✔role (something the user does)
✔✔__________ is the process of assigning authenticated subjects permission to carry
out a specific operation.
Authorization
Identification
Authentication
Accounting - ✔✔Authorization
, ✔✔The security posture of an organization determines the custom settings for access
controls.
True
False - ✔✔True
✔✔In terms of authorization, examples of security labels (based on its classification)
include all EXCEPT:
need to know
confidential
secret
top secret - ✔✔need to know
✔✔__________ is/are mandatory access controls embedded in the object and subject
properties.
Multilayer access
Object capability
Security labels
Access control lists (ACLs) - ✔✔Security labels
✔✔Network Access Control (NAC) can provide the following EXCEPT:
Identity and trust
Instrumentation and management
Policy enforcement
Password management - ✔✔Password management
✔✔As described in NIST Special Publication 800-87, examinations involve forensically
processing large amounts of collected data using a combination of automated and
manual methods to assess and extract data of particular interest, while preserving the
integrity of the data.
True
False - ✔✔True
✔✔Multifactor authentication is when one or more factors are presented.
True
False - ✔✔False
✔✔The key concepts of identification include all BUT: - ✔✔Identities should not be
location-based
SET A+
✔✔In terms of access control, the active entity that requests access to a resource or
data is referred to as the __________.
object
subject
active
entity - ✔✔subject
✔✔The key concepts of identification include all BUT:
Identities should be unique
Identities should not be location-based
Identities should be nondescriptive
Identities should be securely issued - ✔✔Identities should not be location-based
✔✔There are three categories of indentification factors that include all BUT:
knowledge (something the user knows)
possession (something a user has)
role (something the user does)
inherence or characteristics (something the user is) - ✔✔role (something the user does)
✔✔__________ is the process of assigning authenticated subjects permission to carry
out a specific operation.
Authorization
Identification
Authentication
Accounting - ✔✔Authorization
, ✔✔The security posture of an organization determines the custom settings for access
controls.
True
False - ✔✔True
✔✔In terms of authorization, examples of security labels (based on its classification)
include all EXCEPT:
need to know
confidential
secret
top secret - ✔✔need to know
✔✔__________ is/are mandatory access controls embedded in the object and subject
properties.
Multilayer access
Object capability
Security labels
Access control lists (ACLs) - ✔✔Security labels
✔✔Network Access Control (NAC) can provide the following EXCEPT:
Identity and trust
Instrumentation and management
Policy enforcement
Password management - ✔✔Password management
✔✔As described in NIST Special Publication 800-87, examinations involve forensically
processing large amounts of collected data using a combination of automated and
manual methods to assess and extract data of particular interest, while preserving the
integrity of the data.
True
False - ✔✔True
✔✔Multifactor authentication is when one or more factors are presented.
True
False - ✔✔False
✔✔The key concepts of identification include all BUT: - ✔✔Identities should not be
location-based