Latest Exam With All Complete
Solutions.
A corporation's IT department is integrating a new framework that permits, ascertains, and
applies various resources in accordance with established company policies.
Which principle should the department incorporate? - Answer Policy-driven access control
After implementing the National Institute of Standards and Technology (NIST) Cybersecurity
Framework, the chief information security officer (CISO) is assessing the company's security
posture to identify deficiencies from the framework's recommendations.
What process can the CISO run to get a better sense of what the company needs to improve
upon? - Answer Gap analysis
You are a cybersecurity expert implementing a zero trust model in a large organization. You are
tasked with designing the control and data planes.
Which of the following strategies should you prioritize and why? - Answer Balance your focus
between the control and data planes, ensuring both are optimized for security and efficiency.
You want to implement an access control list in which only the users you specifically authorize
have access to the resource. Anyone not on the list should be prevented from having access.
Which of the following methods of access control should the access list use? - Answer Explicit
allow, implicit deny
Which of the following principles is implemented in a mandatory access control model to
determine object access by classification level? - Answer Need to know
What is the primary purpose of separation of duties? - Answer Prevent conflicts of interest.
Which access control model is based on assigning attributes to objects and using Boolean logic
to grant access based on the attributes of the subject? - Answer Attribute-based access control
(ABAC)
You have a system that allows the owner of a file to identify users and their permissions to the
file.