COMPUTER SECURITY CHAPTER 4 QUESTIONS AND ANSWERS | CHAPTER 4
STUDY GUIDE & PRACTICE TEST 2026/2027
T/F: The authentication function determines who is trusted for a given purpose. - ANS ✔✔False
An independent review and examination of system records and activities in order to test for adequacy of
system controls, to ensure compliance with established policy and operational procedures, to detect
breaches in security, and to recommend any indicated changes in control, policy and procedures is a(n)
__________ . - ANS ✔✔Audit
Subject attributes, object attributes and environment attributes are the three types of attributes in the
__________ model. - ANS ✔✔ABAC (Attribute Based Access Control)
A(n) __________ is an entity capable of accessing objects. - ANS ✔✔Subject
__________ implements a security policy that specifies who or what may have access to each specific
system resource and the type of access that is permitted in each instance. - ANS ✔✔Access Control
T/F: Traditional RBAC systems define the access rights of individual users and groups of users. - ANS
✔✔False
The basic elements of access control are: subject, __________, and access right. - ANS ✔✔Object
T/F: An ABAC model can define authorizations that express conditions on properties of both the resource
and the subject. - ANS ✔✔True
A(n) __________ is a mapping between a user and an activated subset of the set of roles to which the
user is assigned. - ANS ✔✔Session
_________ is the granting of a right or permission to a system entity to access a system resource. - ANS
✔✔Authorization
T/F: A user program executes in a kernel mode in which certain areas of memory are protected from the
user's use and certain instructions may not be executed. - ANS ✔✔False
__________ controls access based on comparing security labels with security clearances. - ANS ✔✔MAC
(Mandatory Access Control)
There are three key elements to an ABAC model: attributes which are defined for entities in a
configuration; a policy model, which defines the ABAC policies; and the __________ model, which
applies to policies that enforce access control. - ANS ✔✔Architecture
A __________ access control scheme is one in which an entity may be granted access rights that permit
the entity, by its own volition, to enable another entity to access some resource. - ANS ✔✔Discretionary
STUDY GUIDE & PRACTICE TEST 2026/2027
T/F: The authentication function determines who is trusted for a given purpose. - ANS ✔✔False
An independent review and examination of system records and activities in order to test for adequacy of
system controls, to ensure compliance with established policy and operational procedures, to detect
breaches in security, and to recommend any indicated changes in control, policy and procedures is a(n)
__________ . - ANS ✔✔Audit
Subject attributes, object attributes and environment attributes are the three types of attributes in the
__________ model. - ANS ✔✔ABAC (Attribute Based Access Control)
A(n) __________ is an entity capable of accessing objects. - ANS ✔✔Subject
__________ implements a security policy that specifies who or what may have access to each specific
system resource and the type of access that is permitted in each instance. - ANS ✔✔Access Control
T/F: Traditional RBAC systems define the access rights of individual users and groups of users. - ANS
✔✔False
The basic elements of access control are: subject, __________, and access right. - ANS ✔✔Object
T/F: An ABAC model can define authorizations that express conditions on properties of both the resource
and the subject. - ANS ✔✔True
A(n) __________ is a mapping between a user and an activated subset of the set of roles to which the
user is assigned. - ANS ✔✔Session
_________ is the granting of a right or permission to a system entity to access a system resource. - ANS
✔✔Authorization
T/F: A user program executes in a kernel mode in which certain areas of memory are protected from the
user's use and certain instructions may not be executed. - ANS ✔✔False
__________ controls access based on comparing security labels with security clearances. - ANS ✔✔MAC
(Mandatory Access Control)
There are three key elements to an ABAC model: attributes which are defined for entities in a
configuration; a policy model, which defines the ABAC policies; and the __________ model, which
applies to policies that enforce access control. - ANS ✔✔Architecture
A __________ access control scheme is one in which an entity may be granted access rights that permit
the entity, by its own volition, to enable another entity to access some resource. - ANS ✔✔Discretionary