0% found this document useful (0 votes)
12 views5 pages

Access Control Concepts Quiz

Chapter 3 focuses on access control concepts, including definitions of subjects and various security measures. It presents multiple-choice questions related to physical security controls, user authentication, and policies like segregation of duties. The chapter emphasizes the importance of proper security protocols to protect organizational IT environments.

Uploaded by

alienx1250
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views5 pages

Access Control Concepts Quiz

Chapter 3 focuses on access control concepts, including definitions of subjects and various security measures. It presents multiple-choice questions related to physical security controls, user authentication, and policies like segregation of duties. The chapter emphasizes the importance of proper security protocols to protect organizational IT environments.

Uploaded by

alienx1250
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 3: Access Control

Concepts

Question 1 (1 point)
Which of the following is a subject? (D 3, L3.1.1)
Question 1 options:

A) A file

B) A fence

C) A filename

D) A user

Question 2 (1 point)
Lia works in the security office. During research, Lia learns that a
configuration change could better protect the organization's IT
environment. Lia makes a proposal for this change, but the change
cannot be implemented until it is approved, tested, and then cleared for
deployment by the Change Control Board. This is an example of
__________. (D3, L3.1.1)
Question 2 options:

A) Defense in depth

B) Holistic security
C) Threat intelligence

D) Segregation of duties

Question 3 (1 point)
Duncan and Mira both work in the data center at Triffid, Inc. There is a
policy in place that requires both of them to be present in the data
center at the same time; if one of them has to leave for any reason, the
other has to step out, too, until they can both re-enter. This is called
________. (D 3, L3.1.1)
Question 3 options:

A) Blockade

B) Multifactor authentication

C) Two-person integrity

D) Defense in depth

Question 4 (1 point)
Clyde is the security analyst tasked with finding an appropriate physical
control to reduce the possibility that unbadged people will follow
badged employees through the entrance of the organization's facility.
Which of the following can address this risk? (D3, L3.2.1)
Question 4 options:

A) Fences

B) Dogs
C) Bollards

D) Turnstiles

Question 5 (1 point)
Sinka is considering a physical deterrent control to dissuade
unauthorized people from entering the organization's property. Which
of the following would serve this purpose? (D3, L3.2.1)
Question 5 options:

A) A wall

B) Razor tape

C) A sign

D) A hidden camera

Question 6 (1 point)
Which of these combinations of physical security controls share a single
point of failure? (D3, L3.2.1)
Question 6 options:

A) Guards and fences

B) Badge readers and walls

C) Dogs and bollards

D) High-illumination lighting and cameras


Question 7 (1 point)
Lakshmi presents a userid and a password to a system in order to log
on. Which of the following characteristics must the userid
have? (D3, L3.3.1)
Question 7 options:

A) Confidential

B) Complex

C) Unique

D) Long

Question 8 (1 point)
Lakshmi presents a userid and a password to a system in order to log
on. Which of the following characteristics must the password have?
(D3, L3.3.1)
Question 8 options:

A) Confidential

B) Unique

C) Mathematical

D) Shared

Question 9 (1 point)
Derrick logs on to a system in order to read a file. In this example,
Derrick is the ______. (D3, L3.3.1)
Question 9 options:

A) Subject

B) Object

C) Process

D) Predicate

Question 10 (1 point)
Which is a physical control that prevents "piggybacking" or "tailgating";
that is, an unauthorized person following an authorized person into a
controlled area? (D3, L3.2.1)
Question 10 options:

A) Bollard

B) Turnstile

C) Fence

D) Wall

Common questions

Powered by AI

An organization might opt for high-illumination lighting to deter unauthorized access by making activity in secure areas visible, as it increases the likelihood of malicious actions being noticed by security personnel or captured by surveillance systems. However, this measure could potentially have the vulnerability of a single point of failure if relied upon too heavily without complementary security systems. If the lighting is disabled by malfunction or deliberate sabotage, any area relying solely on illumination for security could become a significant risk point .

A turnstile might be preferred over a fence in situations where controlling and monitoring individual access to a facility is critical. Unlike fences, which serve primarily as barriers, turnstiles can regulate the flow of people, ensuring that only authorized individuals enter the space while preventing 'tailgating' or 'piggybacking' by unauthorized persons. They provide a robust solution for access control by enforcing one-person-at-a-time entry, making them suitable for high-security environments where precise tracking of individuals is necessary .

Bollards and dogs serve as physical security measures by providing deterrence and obstruction, with bollards primarily preventing vehicular access and deliberate ramming attacks, while dogs can detect intrusions and provide active deterrence through presence and noise. However, both share limitations like being unable to independently offer comprehensive perimeter security as they do not prevent or detect unauthorized entry beyond their immediate capability. They rely on human monitoring or additional systems to ensure comprehensive security, and both are limited by environmental conditions such as maintenance or handler availability .

The principle of two-person integrity enhances security by requiring two individuals to be present and agree on actions during operations, thus preventing any single person from undertaking potentially harmful or unauthorized activities unchecked. This principle increases the likelihood of anomalies being detected due to continuous peer oversight, reduces risks of collusion in fraudulent activities, and encourages adherence to protocols due to accountability and mutual accountability among staff members, fostering an environment of trust and checks .

The Change Control Board plays a crucial role in managing security within an organization's IT environment by ensuring that any proposed changes to the system are thoroughly reviewed, tested, and approved before deployment. This process includes identifying potential security enhancements, evaluating their impact, and authorizing changes only after a rigorous evaluation. In the context of Lia's proposal for a configuration change, the Change Control Board ensures that such changes enhance security without disrupting operations or introducing new vulnerabilities .

A password is considered 'confidential' when it is kept secret and known only to the individual it is assigned to. This includes ensuring that the password is not shared, written down in vulnerable locations, or transmitted insecurely. Confidentiality is crucial because it helps preserve the integrity of system access, ensuring that only authorized users can log in and interact with secure systems or data. Maintaining password confidentiality significantly reduces the risk of unauthorized access, data breaches, and compromises .

Requiring two people to be present in the data center during operations, known as two-person integrity, is a security measure designed to prevent unauthorized actions, detect errors promptly, and deter collusion in illegal activities. This policy ensures that no single person can control sensitive operations without oversight, thereby enhancing accountability and reducing risks of malicious activities .

'Piggybacking' or 'tailgating' presents significant risks as it allows unauthorized individuals to enter a controlled area by following closely behind an authorized person, thus bypassing security measures. This risk can be effectively mitigated with physical controls such as turnstiles, which function by allowing only one person to pass at a time and require each person to prove their authorization. Turnstiles enforce the check at every entry, thus preventing multiple persons from entering together undetected, which secures the control of access points .

In access control systems, it is vital for user IDs to be unique to ensure that each user can be distinctly identified and authenticated in the system. This uniqueness prevents identity conflicts, tracks actions accurately for each user, and assists in attributing access and modifications to specific individuals. It supports accountability and audit processes, allowing organizations to trace actions back to the responsible user in case any security incidents or policy violations occur .

'Defense in depth' refers to a multi-layered security strategy designed to protect information by implementing multiple controls across various layers of the IT environment. It focuses on employing diverse protective measures to address different types of threats concurrently. In contrast, 'segregation of duties' specifically aims to separate responsibilities and duties among individuals to minimize the risk of fraud and errors by requiring multiple levels of authorization for critical processes. While defense in depth addresses the breadth of security measures, segregation of duties focuses on in-depth protections against internal threats by dividing potentially conflicting tasks among different people .

You might also like