WGU C845 VUN1 TASK 1 UPDATED
SUBMISSION GUIDE WITH COMPLETE
ANSWERS
◉ What is the benefit of an ABAC over a RBAC?
Answer: An ABAC can be more specific thus more flexible
◉ What is the primary advantage of decentralized access control?
Answer: It provides control of access to people closer to the
resources
◉ How are rules set in ABAC systems?
Answer: Uses boolean logic statements which allow it to be more
flexible than RBAC for temporary rules such as to allow time limited
access.
◉ Which of the following is best described as an access control
model that focuses on subjects and identifies the objects that each
subject can access?
A. Access control list
B. Capability Table
C. Implicit denial list
,D. Rights Management Matrix
Answer: B
◉ Adam is accessing a standalone file server using a username and
password provided by the server administrator. Which one of the
following entities is guaranteed to have information necessary to
complete the authorization process?
A. File Server
B. Adam
C. Server Administrator
D. Adam's Supervisor
Answer: A. The file server has the correct information on what
activities Adam is AUTHORIZED to perform
◉ A new member at a 24 hour gym that uses fingerprints to gain
access after hours is surprised to find out that he is registering as a
different member. What type of biometric factor error occurred?
Answer: Since he was accepted as a different member this was a
Type 2 (false positive) error. If he was not accepted and the door
remained locked it would have been a Type 1 (false negative) error.
◉ You are tasked with adjusting your organizations password
requirements to make them align with best practices from NIST.
What should you set password expiration to?
,Answer: NIST Special Publication 800-63b suggests that
organizations should not impose password expiration requirements
on end users
◉ What access control scheme labels subjects and objects and
allows subjects to access objects when labels match?
Answer: Mandatory Access Control (MAC)
◉ Mandatory Access Control is based on what type of model?
Answer: Lattice Based
◉ You need to create a trust relationship between your company
and a vendor. You need to implement the system so that it will allow
users from the vendor's organization to access your accounts
payable system using the accounts created for them by the vendor.
What type of authentication do you need to implement?
Answer: This type of authentication, where one domain trusts users
from another domain, is called federation.
◉ Users change job positions quite often at your new company.
Which type of access control would make it easier to allow
administrators to adjust permissions when these changes occur?
A. Role-Based Access Control
B. Mandatory Access Control
, C. Discretionary Access Control
D. Rule-Based Access Control
Answer: A Role-Based Access Control would assign permission to
roles and then the administrator would simply adjust the role of the
user when he or she changes jobs
◉ Which of the following authenticators is appropriate to use by
itself rather than in combination with other biometric factors?
A. Voice pattern recognition
B. Hand geometry
C. Palm scans
D. Heart/pulse patterns
Answer: C. Palm scans compare the vein patterns in the palm to a
database to authenticate a user.
◉ As part of hiring a new employee, Sven's identity management
team creates a new user object and ensures that the user object is
available in the directories and systems where it is needed. What is
this process called?
Answer: Provisioning includes the creation, maintenance, and
removal of user objects from applications, systems, and directories.
SUBMISSION GUIDE WITH COMPLETE
ANSWERS
◉ What is the benefit of an ABAC over a RBAC?
Answer: An ABAC can be more specific thus more flexible
◉ What is the primary advantage of decentralized access control?
Answer: It provides control of access to people closer to the
resources
◉ How are rules set in ABAC systems?
Answer: Uses boolean logic statements which allow it to be more
flexible than RBAC for temporary rules such as to allow time limited
access.
◉ Which of the following is best described as an access control
model that focuses on subjects and identifies the objects that each
subject can access?
A. Access control list
B. Capability Table
C. Implicit denial list
,D. Rights Management Matrix
Answer: B
◉ Adam is accessing a standalone file server using a username and
password provided by the server administrator. Which one of the
following entities is guaranteed to have information necessary to
complete the authorization process?
A. File Server
B. Adam
C. Server Administrator
D. Adam's Supervisor
Answer: A. The file server has the correct information on what
activities Adam is AUTHORIZED to perform
◉ A new member at a 24 hour gym that uses fingerprints to gain
access after hours is surprised to find out that he is registering as a
different member. What type of biometric factor error occurred?
Answer: Since he was accepted as a different member this was a
Type 2 (false positive) error. If he was not accepted and the door
remained locked it would have been a Type 1 (false negative) error.
◉ You are tasked with adjusting your organizations password
requirements to make them align with best practices from NIST.
What should you set password expiration to?
,Answer: NIST Special Publication 800-63b suggests that
organizations should not impose password expiration requirements
on end users
◉ What access control scheme labels subjects and objects and
allows subjects to access objects when labels match?
Answer: Mandatory Access Control (MAC)
◉ Mandatory Access Control is based on what type of model?
Answer: Lattice Based
◉ You need to create a trust relationship between your company
and a vendor. You need to implement the system so that it will allow
users from the vendor's organization to access your accounts
payable system using the accounts created for them by the vendor.
What type of authentication do you need to implement?
Answer: This type of authentication, where one domain trusts users
from another domain, is called federation.
◉ Users change job positions quite often at your new company.
Which type of access control would make it easier to allow
administrators to adjust permissions when these changes occur?
A. Role-Based Access Control
B. Mandatory Access Control
, C. Discretionary Access Control
D. Rule-Based Access Control
Answer: A Role-Based Access Control would assign permission to
roles and then the administrator would simply adjust the role of the
user when he or she changes jobs
◉ Which of the following authenticators is appropriate to use by
itself rather than in combination with other biometric factors?
A. Voice pattern recognition
B. Hand geometry
C. Palm scans
D. Heart/pulse patterns
Answer: C. Palm scans compare the vein patterns in the palm to a
database to authenticate a user.
◉ As part of hiring a new employee, Sven's identity management
team creates a new user object and ensures that the user object is
available in the directories and systems where it is needed. What is
this process called?
Answer: Provisioning includes the creation, maintenance, and
removal of user objects from applications, systems, and directories.