Models with questions and correct verified
answers 2025-2026
TRUE/FALSE
1. A security blueprint is the outline of the more thorough security framework.
CORRECT ANSWER: T MARKS: 1
2. Separation of duties is the principle by which members of the organization can access the
minimum amount of information for the minimum amount of time necessary to perform their
required duties.
CORRECT ANSWER: F MARKS: 1
3. Lattice-based access control specifies the level of access each subject has to each object, if any.
CORRECT ANSWER: T MARKS: 1
4. Under the Clark-Wilson model, internal consistency me correct answer that the system is
consistent with similar data in the outside world.
CORRECT ANSWER: F MARKS: 1
5. Information Technology Infrastructure Library provides guidance in the development and
implementation of an organizational InfoSec governance structure.
CORRECT ANSWER: F MARKS: 1
MULTIPLE CHOICE
1. Which of the following is a generic blueprint offered by a service organization which must be
flexible, scalable, robust, and detailed?
a. framework c. organizational model
b. security outline d. security model
CORRECT ANSWER: D MARKS: 1
2. Which access control principle specifies that members of the organization can access the
minimum amount of information for the minimum amount of time necessary to perform their
required duties?
a. need-to-know c. least privilege
b. eyes only d. separation of duties
CORRECT ANSWER: C MARKS: 1
3. Which access control principle limits a user’s access to the specific information required to
perform the currently assigned task?
a. need-to-know c. least privilege
,b. eyes only d. separation of duties
, CORRECT ANSWER: A MARKS: 1
4. Controls that remedy a circumstance or mitigate damage done during an incident are categorized
as which of the following?
a. preventative c. corrective
b. deterrent d. compensating
CORRECT ANSWER: C MARKS: 1
Which of the following is NOT a category of access control?
a. preventative c. deterrent
b. remitting d. compensating
CORRECT ANSWER: B MARKS: 1
5. Which control category discourages an incipient incident?
a. preventative c. remitting
b. deterrent d. compensating
CORRECT ANSWER: B MARKS: 1
6. Which of the following is NOT one of the five levels in the U.S. military data classification
scheme?
a. confidential c. top secret
b. secret d. private
CORRECT ANSWER: D MARKS: 1
7. Which of the following specifies the authorization classification of information asset an
individual user is permitted to access, subject to the need-to-know principle?
a. Discretionary access c. Security clearances
controls
b. Task-based access d. Sensitivity levels
controls
CORRECT ANSWER: C MARKS: 1
8. Which type of access controls can be role-based or task-based?
a. constrained c. nondiscretionary
b. content-dependent d. discretionary
CORRECT ANSWER: C MARKS: 1
Under lattice-based access controls, the column of attributes associated with a particular object
(such as a printer) is referred to as which of the following?
a. access control list c. access matrix
b. capabilities table d. sensitivity level
CORRECT ANSWER: A MARKS: 1
9. In which form of access control is access to a specific set of information dependent on its subject
matter?
, a. content-dependent c. temporal isolation
access controls
b. constrained user d. None of these
interfaces
CORRECT ANSWER: A MARKS: 1
10. A time-release safe is an example of which type of access control?
a. content-dependent c. temporal isolation
b. constrained user d. nondiscretionary
interface
CORRECT ANSWER: C MARKS: 1
11. Which security architecture model is part of a larger series of standards collectively referred to as
the “Rainbow Series”?
a. Bell-LaPadula c. ITSEC
b. TCSEC d. Common Criteria
CORRECT ANSWER: B MARKS: 1
12. Which piece of the TCSEC system manages access controls?
a. trusted computing base c. covert channel
b. reference monitor d. verification module
CORRECT ANSWER: B MARKS: 1
13. Under the Common Criteria, which term specifies the user-generated specifications for security
requirements?
a. Target of Evaluation (ToE)
b. Protection Profile (PP)
c. Security Target (ST)
d. Security Functional Requirements (SFRs)
CORRECT ANSWER: B MARKS: 1
Which security architecture model is based on the premise that higher levels of integrity are more
worthy of trust than lower ones?
a. Clark-Wilson c. Common Criteria
b. Bell-LaPadula d. Biba
CORRECT ANSWER: D MARKS: 1
14. Which of the following is NOT a change control principle of the Clark-Wilson model?
a. No changes by unauthorized subjects
b. No unauthorized changes by authorized subjects
c. No changes by authorized subjects without
external validation
d. The maintenance of internal and external
consistency