• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 1 fuera de 3 páginas
Examen

IT Infrastructure Security Policies Review Questions with complete Solutions Rated A+

Document preview thumbnail
Vista previa 1 fuera de 3 páginas

IT Infrastructure Security Policies Review Questions with complete Solutions Rated A+ access controls - Answers security features that govern how users and processes communicate and interact with systems and resources three common attributes of access controls - Answers identification scheme authentication method authorization method security posture - Answers it is the organization's approach to access control two fundamentals security postures - Answers secure, which implements the "default deny" model open, which implements the "default allow" model default allow - Answers by default, out of the box, no security is deployed, everyone can do everything (easier to deploy, no security) default deny - Answers aka "deny all", access is unavailable by default until the appropriate control is altered to allow access principle of least privilege - Answers the least amount of permissions granted users that still allow them to perform whatever business tasks they have been assigned, and no more protects the data but also protects users, they can't be accused of having deleted a file to which they can't gain access authentication - Answers subject must supply verifiable credentials offered referred as factors single-factor multifactor three categories of factors - Answers knowledge - something you know (PIN, password, etc.) possession - something you have (OTP, smart cards, memory cards) inherence - something you are (biometrics) three primary authorization models - Answers object capability - used programatically and based on a combination of a unforgettable reference and an operational message security labels - mandatory access controls embedded in object and subject properties access control lists - used to determine access based on some criteria mandatory access control (MAC) - Answers data is classified, and employees are granted access according to the sensitivity of information discretionary access control (DAC) - Answers data owners decide who should have access to what information role-based access control (RBAC) - Answers access is based on positions (roles) within an organization rule-based access control - Answers access is based on criteria that is independent of the user or group account network segmentation - Answers the process of logically grouping network assets, resources, and applications types of network segmentation: enclave network

Vista previa del contenido

IT Infrastructure Security Policies Review Questions with complete Solutions Rated A+

access controls - Answers security features that govern how users and processes communicate and
interact with systems and resources

three common attributes of access controls - Answers identification scheme

authentication method

authorization method

security posture - Answers it is the organization's approach to access control

two fundamentals security postures - Answers secure, which implements the "default deny" model

open, which implements the "default allow" model

default allow - Answers by default, out of the box, no security is deployed, everyone can do everything
(easier to deploy, no security)

default deny - Answers aka "deny all", access is unavailable by default until the appropriate control is
altered to allow access

principle of least privilege - Answers the least amount of permissions granted users that still allow them
to perform whatever business tasks they have been assigned, and no more



protects the data but also protects users, they can't be accused of having deleted a file to which they
can't gain access

authentication - Answers subject must supply verifiable credentials offered referred as factors

single-factor

multifactor

three categories of factors - Answers knowledge - something you know (PIN, password, etc.)



possession - something you have (OTP, smart cards, memory cards)



inherence - something you are (biometrics)

three primary authorization models - Answers object capability - used programatically and based on a
combination of a unforgettable reference and an operational message

Información del documento

Subido en
11 de octubre de 2024
Número de páginas
3
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$8.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
TutorJosh
3.5
(76)
Vendido
497
Seguidores
16
Artículos
32947
Última venta
20 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes