WGU C845 VUN1 TASK 1 ASSESSMENT
REVIEW QUESTIONS AND CORRECT
ANSWERS
◉ job rotation.
Answer: The act of shifting individuals between roles and
responsibilities to prohibit security violations
◉ least privilege.
Answer: Security principle that individuals are provided with the
least amount of information required to perform their jobs or duties
◉ mandatory vacation.
Answer: A security control that allows the monitoring of business
functions without the availability of a principal or responsible
individual
◉ separation of duties.
Answer: A security program in which two or more people are
required to independently perform activities to complete an action
◉ user ID.
,Answer: An assigned identification. Every user of the system should
have a unique user ID. Its use must still be authenticated
◉ certification.
Answer: The successful conclusion after a system or application has
been tested against preestablished standards
◉ vulnerability assessment.
Answer: The organized set of steps used to identify and analyse
threats and vulnerabilities to determine an organization's overall
risk
◉ access control list (ACL).
Answer: A list of subjects and assigned rights used in access control.
◉ administrative controls.
Answer: Controls put in place to enforce policies and directives as
dictated by the organization
◉ biometrics.
Answer: Hardware or software used to measure human
characteristics as part of an authentication system
,◉ data at rest.
Answer: Any data in a storage location and not moving between
locations or being processed by an application.
◉ defense diversity.
Answer: The use of two devices from separate vendors. For instance,
the use of two firewalls that provide slightly different services or
rules in order to support the defense in-depth strategy
◉ defense in depth.
Answer: A layered approach to defense. The placement of several
controls in a series in an effort to slow down, discourage, or
eliminate an attacker
◉ false acceptance rate (FAR).
Answer: An authentication error rate in which an unknown user is
identified as a known user and is mistakenly allowed access. Also
referred to as a Type II biometric error
◉ false rejection rate (FRR).
Answer: An authentication error rate in which a known user is
identified as an unknown user and is mistakenly denied access. Also
referred to as a Type I biometric error
, ◉ Kerberos.
Answer: A single sign-on technology that includes a ticket-granting
server, ticket-granting tickets, and session tickets. It provides users
access to authorized resources based upon the one-time
authentication of their credentials
◉ logical access control.
Answer: Electronic hardware or software that limits users' access to
only the resources to which they have been given authorization
◉ logical/technical controls.
Answer: Electronic hardware or software controls that are placed in
a network to mitigate risk
◉ mandatory access control.
Answer: An access control methodology that requires the subject as
well as the object to be assigned a label. During an access process
the labels are "mediated," or compared by an application, device, or
system that determines access. For instance, a subject with a top-
secret label wanting to access an object with a top-secret label must
be mediated or allowed access by a system, usually referred to as a
trusted computing base. In less critical systems an access control list
may be used
◉ multifactor authentication.
REVIEW QUESTIONS AND CORRECT
ANSWERS
◉ job rotation.
Answer: The act of shifting individuals between roles and
responsibilities to prohibit security violations
◉ least privilege.
Answer: Security principle that individuals are provided with the
least amount of information required to perform their jobs or duties
◉ mandatory vacation.
Answer: A security control that allows the monitoring of business
functions without the availability of a principal or responsible
individual
◉ separation of duties.
Answer: A security program in which two or more people are
required to independently perform activities to complete an action
◉ user ID.
,Answer: An assigned identification. Every user of the system should
have a unique user ID. Its use must still be authenticated
◉ certification.
Answer: The successful conclusion after a system or application has
been tested against preestablished standards
◉ vulnerability assessment.
Answer: The organized set of steps used to identify and analyse
threats and vulnerabilities to determine an organization's overall
risk
◉ access control list (ACL).
Answer: A list of subjects and assigned rights used in access control.
◉ administrative controls.
Answer: Controls put in place to enforce policies and directives as
dictated by the organization
◉ biometrics.
Answer: Hardware or software used to measure human
characteristics as part of an authentication system
,◉ data at rest.
Answer: Any data in a storage location and not moving between
locations or being processed by an application.
◉ defense diversity.
Answer: The use of two devices from separate vendors. For instance,
the use of two firewalls that provide slightly different services or
rules in order to support the defense in-depth strategy
◉ defense in depth.
Answer: A layered approach to defense. The placement of several
controls in a series in an effort to slow down, discourage, or
eliminate an attacker
◉ false acceptance rate (FAR).
Answer: An authentication error rate in which an unknown user is
identified as a known user and is mistakenly allowed access. Also
referred to as a Type II biometric error
◉ false rejection rate (FRR).
Answer: An authentication error rate in which a known user is
identified as an unknown user and is mistakenly denied access. Also
referred to as a Type I biometric error
, ◉ Kerberos.
Answer: A single sign-on technology that includes a ticket-granting
server, ticket-granting tickets, and session tickets. It provides users
access to authorized resources based upon the one-time
authentication of their credentials
◉ logical access control.
Answer: Electronic hardware or software that limits users' access to
only the resources to which they have been given authorization
◉ logical/technical controls.
Answer: Electronic hardware or software controls that are placed in
a network to mitigate risk
◉ mandatory access control.
Answer: An access control methodology that requires the subject as
well as the object to be assigned a label. During an access process
the labels are "mediated," or compared by an application, device, or
system that determines access. For instance, a subject with a top-
secret label wanting to access an object with a top-secret label must
be mediated or allowed access by a system, usually referred to as a
trusted computing base. In less critical systems an access control list
may be used
◉ multifactor authentication.