Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 5 pages
Exam (elaborations)

CISSP DOMAIN 1 EXAM QUESTIONS WITH 100% CORRECT ANSWERS

Document preview thumbnail
Preview 2 out of 5 pages

CISSP DOMAIN 1 EXAM QUESTIONS WITH 100% CORRECT ANSWERS

Content preview

CISSP DOMAIN 1 EXAM QUESTIONS
WITH 100% CORRECT ANSWERS

Type of controls used to protect access to the physical facilities housing information
systems. - Answer- Physical controls

States that the subjects of an access control system should have the minimum set of
access permissions necessary to complete their assigned job functions. - Answer-
Principle of least privilege

The ability to perform critical system functions should be divided among different
individuals to minimize the risk of collusion. - Answer- Separation of duties

Users should only have access to information that they have a need to know to perform
their assigned responsibilities. - Answer- Need to know

Users gain different access permissions as they move from position to position in an
organization but old permissions are not revoked. - Answer- Privilege creep

Authorization of the subjects access to an object depends on labels which indicate a
subjects clearance and the classification or sensitivity of the related object - Answer-
Mandatory access control (MAC)

Access control type where the subject has authority to specify what objects can be
accessible. - Answer- Discretionary access control (DAC)

Access control type where the Administrator determines which subjects can have
access to certain objects based on an organizations security policy. - Answer- Non-
discretionary access control (NDAC) also known as role based access control (RBAC)

Access control type where the administrator specifies upper and lower bounds of the
authority for each subject and uses those boundaries to determine access permissions.
- Answer- Lattice based access control (LBAC)

Four types of access control systems. - Answer- MAC, DAC, NDAC (RBAC), LBAC

A central authentication and/or authorization point for an enterprise. - Answer-
Centralized access control system

A series of diverse access control systems at different points throughout the enterprise.
- Answer- Decentralized access control systems

, Technology that enables centralized authentication. - Answer- Single sign on (SSO)

Software used on a network to establish a users identity. - Answer- Kerberos

Three components of kerberos - Answer- Key distribution center (KDC), Authentication
service (AS), Ticket granting service (TGS)

A public key based alternative to kerberos - Answer- SESAME

Three authentication factors. - Answer- Something you know, something you have,
something you are

Using at least two authentication factors. - Answer- Two-factor authentication

The most commonly implemented authentication technique. - Answer- Passwords

Four different kinds of tokens - Answer- Static password, synchronous dynamic
password, asynchronous dynamic password, challenge-response token

Token type where the owner authenticates himself to the token and the token
authenticates the owner to the system. - Answer- Static password token

Token type where the token generates a new unique password at fixed time intervals,
user enters a unique password and user name into the system, and the system
confirms that the password and user name are correct and were entered during the
allowed time interval. - Answer- Synchronous dynamic password token


User makes a claim as to his or her identity. - Answer- Identification

User proves his or her identity using one or more mechanisms. - Answer- Authentication

System makes decisions about what resources the user is allowed to access and the
manner in which they may be manipulated. - Answer- Authorization

System keeps an accurate audit trail of the users activity. - Answer- Accounting

Entities that may be assigned permissions. - Answer- Subjects

Types of resources that subjects may access. - Answer- Objects

Relationships between subjects and the objects they may access. - Answer- Access
permissions

Contains access control entities (ACEs) that correspond to access permissions. -
Answer- Access control list (ACL)

Document information

Uploaded on
September 5, 2025
Number of pages
5
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Scholarsstudyguide
3.8
(169)
Sold
838
Followers
475
Items
16312
Last sold
3 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions