EPISODE · Jan 21, 2025 · 18 MIN
ISC2 CC Domain 3: Access Control Study Exam Questions by Edward Henriquez
from Decoded: The Cybersecurity Podcast · host Edward Henriquez
Domain 3: Access Control Concepts Example of logical access control:A. Security guardsB. Biometric authenticationC. PasswordsD. Fire alarmsAnswer: C Multi-factor authentication (MFA) requires:A. Two or more forms of authentication from different categoriesB. The same password used in multiple placesC. Multiple users authenticating simultaneouslyD. A combination of encryption methodsAnswer: A Access control based on job roles:A. Discretionary Access Control (DAC)B. Role-Based Access Control (RBAC)C. Attribute-Based Access Control (ABAC)D. Mandatory Access Control (MAC)Answer: B Access control granting permissions based on attributes like location:A. Attribute-Based Access Control (ABAC)B. Role-Based Access Control (RBAC)C. Mandatory Access Control (MAC)D. Discretionary Access Control (DAC)Answer: A Access control using predefined rules/labels:A. Discretionary Access Control (DAC)B. Role-Based Access Control (RBAC)C. Mandatory Access Control (MAC)D. Attribute-Based Access Control (ABAC)Answer: C Principle of least privilege:A. Giving users only necessary permissionsB. Allowing administrators unlimited accessC. Preventing user account creationD. Implementing mandatory security clearancesAnswer: A Time-based access control:A. Granted only during specific hoursB. Determined by user roleC. Restricted to known locationsD. Granted after authentication expiresAnswer: A Centralized server enforcing access control policies:A. FirewallB. Directory ServiceC. Proxy ServerD. Load BalancerAnswer: B Attack using stolen session token:A. Brute forceB. Replay attackC. Session hijackingD. PhishingAnswer: C Access control model where users can grant/restrict access:A. Discretionary Access Control (DAC)B. Mandatory Access Control (MAC)C. Role-Based Access Control (RBAC)D. Attribute-Based Access Control (ABAC)Answer: A Purpose of a password policy:A. Encrypt filesB. Enforce secure password creation/managementC. Monitor login attemptsD. Limit account creationAnswer: B “Something you have” in MFA:A. PasswordB. Smart cardC. BiometricsD. PINAnswer: B Risk of sharing user credentials:A. Loss of password integrityB. Violation of encryption standardsC. Increased bandwidth usageD. Unauthorized accessAnswer: D Purpose of account lockout policies:A. Block malicious trafficB. Prevent brute force attacksC. Encrypt sensitive dataD. Monitor login attemptsAnswer: B Access control dynamically adjusting access by location:A. Attribute-Based Access Control (ABAC)B. Role-Based Access Control (RBAC)C. Mandatory Access Control (MAC)D. Discretionary Access Control (DAC)Answer: A Primary purpose of biometric authentication:A. Enhance encryptionB. Verify physical characteristicsC. Monitor network trafficD. Backup critical dataAnswer: B Granting temporary access:A. Privilege escalationB. Time-bound accessC. User provisioningD. Conditional accessAnswer: B Attack manipulating users to share confidential data:A. MalwareB. Social engineeringC. PhishingD. KeyloggingAnswer: B Preventing password reuse:A. Multi-factor authenticationB. Password history policiesC. Single sign-onD. EncryptionAnswer: B Primary function of access control logs:A. Block unauthorized usersB. Record access attemptsC. Update user rolesD. Enforce encryptionAnswer: B Purpose of a firewall:A. Detect malwareB. Filter traffic between networksC. Encrypt sensitive informationD. Manage bandwidthAnswer: B Attack flooding a network to disrupt resources:A. Man-in-the-middleB. PhishingC. Denial of Service (DoS)D. ReplayAnswer: C
Embed this episode
NOW PLAYING
ISC2 CC Domain 3: Access Control Study Exam Questions by Edward Henriquez
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.