CNIT 242 FINAL EXAM | 468 QUESTIONS AND ANSWERS |
2026 UPDATE | WITH COMPLETE SOLUTION.
What does AAA stand for? Answer - Authentication, Authorization, and
Accounting
What question does Authentication answer? Answer - Do you have the
credentials necessary to access this system?
What question does Authorization answer? Answer - Once authenticated,
what do you have permission to do?
What question does Accounting answer? Answer - Once authorized to access a
resource, how much of the resource are you using?
Authentication can be accomplished using any of what 4 qualifications? Answer
- What you know, what you have, what you are, where you are
What is two-factor authentication? Answer - Using two of the 4 authentication
qualifications to prove an identity.
What 2 steps does the authentication process involve? Answer - Identification
and proof of identification
,What are ways to provide identification? Answer - User ID, physical object
(such as ATM card), biometrics, digital certificates
What are ways to provide proof of identification? Answer - passwords, access
codes, one-time tokens, biometrics, digital certificates
What are strategic ways to develop user IDs? Answer - computer generated
(NEVER simple names), sometimes created to some algorithm, NEVER use the
same as email address
True or False: UID / password combo can be a powerful method of
authentication if properly managed Answer - True
What is the number one rule of password security? Answer - DON'T WRITE
PASSWORDS DOWN
What is the security tradeoff with password? Answer - The more strict the
password rules, the higher the chances users will violate the first rule of secure
passwords
What are biometrics? Answer - authentication. functions as both ID and proof
of ID, separated into physiological and behavioral
What are digital certificates? Answer - a form of authentication. encrypted
data files that uses a Certificate Authority to guarantee the identity of the
holder
What does RADIUS stand for and what does it provide? Answer - Remote
Access Dial-In User Service, both Authentication and Authorization
,What does TACAS+ stand for? Answer - Terminal Access Controller Access
Control Service Plus
Where does authentication across the network exist? Answer - on the local
computer by default, but in an enterprise environment, it will be on a different
server
In a domain environment, what is authenticated against? Answer - the
domain, not the local machine
How is authorization accomplished? Answer - through rights and permissions
What level do group policies assign rights to? Answer - system
What level do access control lists assign permissions to? Answer - object
What is an access control list? Answer - simplest method of providing
authorization, but requires a separate authentication method. they are
attached to/located on the resource
What do ACLs contain? Answer - a list of authorized users and their
authorization levels
When do "share" permissions apply? Answer - when the resource is accessed
over a network
What 3 servers does Kerberos require? Answer - one authentication server,
one ticket granting server, and at least one application server
, What is the basic concept of Kerberos? Answer - If a secret is known by only
two people, either person can verify the identity of the other by confirming
that the other person knows the secret.
What is the purpose of a Kerberos Realm? Answer - admins create the realms
which encompass all that is available to access. a realm defines what Kerberos
manages in terms of who can access what.
What is within a Kerberos Realm? Answer - Within the realm is the Client and
the service/host machine to which they requested access. There is also the Key
Distribution Center which hold the Authentication S and TGS
In Kerberos, when requesting access to a service or host, three interactions
take place between you and: Answer - the Authentication Server, the Ticket
Granting Server, and the Service or host machine that you're wanting access to
What will you receive with each interaction in Kerberos? Answer - Two
messages. Each message is one that you can decrypt, and one that you can not.
In Kerberos, does the service/machine you are requesting access to
communicate directly with the KDC? Answer - No, they do not!
Where are all the secret keys for user machines and services stored in
Kerberos? Answer - the KDC
What are secret keys (in Kerberos)? Answer - passwords plus a salt that are
hashed
True or False: There are passwords on the services/host machines that use
Kerberos. Answer - False
2026 UPDATE | WITH COMPLETE SOLUTION.
What does AAA stand for? Answer - Authentication, Authorization, and
Accounting
What question does Authentication answer? Answer - Do you have the
credentials necessary to access this system?
What question does Authorization answer? Answer - Once authenticated,
what do you have permission to do?
What question does Accounting answer? Answer - Once authorized to access a
resource, how much of the resource are you using?
Authentication can be accomplished using any of what 4 qualifications? Answer
- What you know, what you have, what you are, where you are
What is two-factor authentication? Answer - Using two of the 4 authentication
qualifications to prove an identity.
What 2 steps does the authentication process involve? Answer - Identification
and proof of identification
,What are ways to provide identification? Answer - User ID, physical object
(such as ATM card), biometrics, digital certificates
What are ways to provide proof of identification? Answer - passwords, access
codes, one-time tokens, biometrics, digital certificates
What are strategic ways to develop user IDs? Answer - computer generated
(NEVER simple names), sometimes created to some algorithm, NEVER use the
same as email address
True or False: UID / password combo can be a powerful method of
authentication if properly managed Answer - True
What is the number one rule of password security? Answer - DON'T WRITE
PASSWORDS DOWN
What is the security tradeoff with password? Answer - The more strict the
password rules, the higher the chances users will violate the first rule of secure
passwords
What are biometrics? Answer - authentication. functions as both ID and proof
of ID, separated into physiological and behavioral
What are digital certificates? Answer - a form of authentication. encrypted
data files that uses a Certificate Authority to guarantee the identity of the
holder
What does RADIUS stand for and what does it provide? Answer - Remote
Access Dial-In User Service, both Authentication and Authorization
,What does TACAS+ stand for? Answer - Terminal Access Controller Access
Control Service Plus
Where does authentication across the network exist? Answer - on the local
computer by default, but in an enterprise environment, it will be on a different
server
In a domain environment, what is authenticated against? Answer - the
domain, not the local machine
How is authorization accomplished? Answer - through rights and permissions
What level do group policies assign rights to? Answer - system
What level do access control lists assign permissions to? Answer - object
What is an access control list? Answer - simplest method of providing
authorization, but requires a separate authentication method. they are
attached to/located on the resource
What do ACLs contain? Answer - a list of authorized users and their
authorization levels
When do "share" permissions apply? Answer - when the resource is accessed
over a network
What 3 servers does Kerberos require? Answer - one authentication server,
one ticket granting server, and at least one application server
, What is the basic concept of Kerberos? Answer - If a secret is known by only
two people, either person can verify the identity of the other by confirming
that the other person knows the secret.
What is the purpose of a Kerberos Realm? Answer - admins create the realms
which encompass all that is available to access. a realm defines what Kerberos
manages in terms of who can access what.
What is within a Kerberos Realm? Answer - Within the realm is the Client and
the service/host machine to which they requested access. There is also the Key
Distribution Center which hold the Authentication S and TGS
In Kerberos, when requesting access to a service or host, three interactions
take place between you and: Answer - the Authentication Server, the Ticket
Granting Server, and the Service or host machine that you're wanting access to
What will you receive with each interaction in Kerberos? Answer - Two
messages. Each message is one that you can decrypt, and one that you can not.
In Kerberos, does the service/machine you are requesting access to
communicate directly with the KDC? Answer - No, they do not!
Where are all the secret keys for user machines and services stored in
Kerberos? Answer - the KDC
What are secret keys (in Kerberos)? Answer - passwords plus a salt that are
hashed
True or False: There are passwords on the services/host machines that use
Kerberos. Answer - False