SSCP: Systems Security Certified
Practitioner Access Controls
Authentication applies to - Answer-Users, applications and devices
Authentication is the process of - Answer-proving identity in order to gain access to a resource
Authentication proves what - Answer-entity attempting to log on is who / what they claim to be
Authentication limits - Answer-access to only those who should have it
Authentication lets administrators do what - Answer-set limitations on what users gain access to
Most common type of authentication - Answer-something you know, something you have, something
you are
Something you know - Answer-passwords and pins
, Password best practice - Answer-strong, do not write down, never share, audit for strength and
changed at set intervals
Something you have - Answer-proximity cards, smart cards, hardware tokens, ID bodges
Something you are - Answer-Biometrics
Biometrics challenges - Answer-error rates
Single factor authentication is - Answer-using only one factor of authentication
Single factor authentication can use what type of authentication? - Answer-either something you know,
something you have, something you are
Multifactor Authentication is the use of what - Answer-more than one factor of authentication
SSO - Answer-Single Sign-On
SSO allows what? - Answer-user to access multiple systems, resources and applications by one login
SSO advantage - Answer-simplifies identity management and no multiple logins required
SSO uses what? - Answer-Central DB or Directory to store users ID and credentials
A token can be used for what? - Answer-granting user access to all relevant resources
Practitioner Access Controls
Authentication applies to - Answer-Users, applications and devices
Authentication is the process of - Answer-proving identity in order to gain access to a resource
Authentication proves what - Answer-entity attempting to log on is who / what they claim to be
Authentication limits - Answer-access to only those who should have it
Authentication lets administrators do what - Answer-set limitations on what users gain access to
Most common type of authentication - Answer-something you know, something you have, something
you are
Something you know - Answer-passwords and pins
, Password best practice - Answer-strong, do not write down, never share, audit for strength and
changed at set intervals
Something you have - Answer-proximity cards, smart cards, hardware tokens, ID bodges
Something you are - Answer-Biometrics
Biometrics challenges - Answer-error rates
Single factor authentication is - Answer-using only one factor of authentication
Single factor authentication can use what type of authentication? - Answer-either something you know,
something you have, something you are
Multifactor Authentication is the use of what - Answer-more than one factor of authentication
SSO - Answer-Single Sign-On
SSO allows what? - Answer-user to access multiple systems, resources and applications by one login
SSO advantage - Answer-simplifies identity management and no multiple logins required
SSO uses what? - Answer-Central DB or Directory to store users ID and credentials
A token can be used for what? - Answer-granting user access to all relevant resources