Security Management Exam 1
questions well answered
Access Control - correct answer ✔✔ Not merely controlling user access to files or services. The
relationship between subjects and objects. Mission: Protect the confidentiality, integrity, and
availability of objects.
7 Types of access control - correct answer ✔✔ Preventive, Recovery, Deterrent, Compensation,
Detective, Directive, Corrective
The process of Accountability - correct answer ✔✔ Identification of subject
Authentication
*Type 1: What you know
*Type 2: What you have
*Type 3: What you are
Authorization of access
*Assigned rights and privelages
Auditing
Passwords - correct answer ✔✔ Strings of characters typed to authenticate someone wanting to
use a username (account) on a computer.
Benefits - correct answer ✔✔ Ease of use for users (familiar). Inexpensive because built in to
operating systems.
Biometric Factor Ratings - correct answer ✔✔ Type 1 Error: valid subject is not authenticated.
False rejection rate.
, Type 2 Error: Invalid subject is authenticated. False acceptance rate.
Equal Error Rate: FRR =FAR Low on the graph is most accurate.
Access Control Methodologies - correct answer ✔✔ Centralized: Managed by a team or
individual. Single Location. Single point of failure.
Decentralized: Managed by several teams or individuals. Multiple locations. Administration is
difficult.
Separation of Duties - correct answer ✔✔ Multiple subjects verify each others actions.
Attack Methodologies - correct answer ✔✔ Brute Force & Dictionary Lookup; Sniffing attacks;
Spoofing attacks; Social Engineering; Denial of Service;
Monitoring - correct answer ✔✔ Necessary to detect malicious actions by subjects. Part of the
auditing stage of the subject accountability process. Sources of Information
Detecting Unauthorized Access - correct answer ✔✔ Intrusion Detection System (IDSs): Host
based IDSs monitor all activity on the server as well as incoming server traffic. Network based
IDSs Install IDS sensors on network circuits and monitor packets. Reports intrusions to IDS
Management Console.
Methods Used by IDSs - correct answer ✔✔ Knowledge Based: also called signature based.
Behavior Based: also called anomaly based.
IDS vs Firewalls? - correct answer ✔✔ Firewalls = Reactive "responding to traffic"
IDS=Active, Passive, or Hybrid "responding to patterns". Both operations can be housed in the
same device.
questions well answered
Access Control - correct answer ✔✔ Not merely controlling user access to files or services. The
relationship between subjects and objects. Mission: Protect the confidentiality, integrity, and
availability of objects.
7 Types of access control - correct answer ✔✔ Preventive, Recovery, Deterrent, Compensation,
Detective, Directive, Corrective
The process of Accountability - correct answer ✔✔ Identification of subject
Authentication
*Type 1: What you know
*Type 2: What you have
*Type 3: What you are
Authorization of access
*Assigned rights and privelages
Auditing
Passwords - correct answer ✔✔ Strings of characters typed to authenticate someone wanting to
use a username (account) on a computer.
Benefits - correct answer ✔✔ Ease of use for users (familiar). Inexpensive because built in to
operating systems.
Biometric Factor Ratings - correct answer ✔✔ Type 1 Error: valid subject is not authenticated.
False rejection rate.
, Type 2 Error: Invalid subject is authenticated. False acceptance rate.
Equal Error Rate: FRR =FAR Low on the graph is most accurate.
Access Control Methodologies - correct answer ✔✔ Centralized: Managed by a team or
individual. Single Location. Single point of failure.
Decentralized: Managed by several teams or individuals. Multiple locations. Administration is
difficult.
Separation of Duties - correct answer ✔✔ Multiple subjects verify each others actions.
Attack Methodologies - correct answer ✔✔ Brute Force & Dictionary Lookup; Sniffing attacks;
Spoofing attacks; Social Engineering; Denial of Service;
Monitoring - correct answer ✔✔ Necessary to detect malicious actions by subjects. Part of the
auditing stage of the subject accountability process. Sources of Information
Detecting Unauthorized Access - correct answer ✔✔ Intrusion Detection System (IDSs): Host
based IDSs monitor all activity on the server as well as incoming server traffic. Network based
IDSs Install IDS sensors on network circuits and monitor packets. Reports intrusions to IDS
Management Console.
Methods Used by IDSs - correct answer ✔✔ Knowledge Based: also called signature based.
Behavior Based: also called anomaly based.
IDS vs Firewalls? - correct answer ✔✔ Firewalls = Reactive "responding to traffic"
IDS=Active, Passive, or Hybrid "responding to patterns". Both operations can be housed in the
same device.