ISC2 CC Domain 3: Access Control Study Exam Questions by Edward Henriquez episode artwork

EPISODE · Jan 21, 2025 · 18 MIN

ISC2 CC Domain 3: Access Control Study Exam Questions by Edward Henriquez

from Decoded: The Cybersecurity Podcast · host Edward Henriquez

Domain 3: Access Control Concepts​ Example of logical access control:A. Security guardsB. Biometric authenticationC. PasswordsD. Fire alarmsAnswer: C​ Multi-factor authentication (MFA) requires:A. Two or more forms of authentication from different categoriesB. The same password used in multiple placesC. Multiple users authenticating simultaneouslyD. A combination of encryption methodsAnswer: A​ Access control based on job roles:A. Discretionary Access Control (DAC)B. Role-Based Access Control (RBAC)C. Attribute-Based Access Control (ABAC)D. Mandatory Access Control (MAC)Answer: B​ Access control granting permissions based on attributes like location:A. Attribute-Based Access Control (ABAC)B. Role-Based Access Control (RBAC)C. Mandatory Access Control (MAC)D. Discretionary Access Control (DAC)Answer: A​ Access control using predefined rules/labels:A. Discretionary Access Control (DAC)B. Role-Based Access Control (RBAC)C. Mandatory Access Control (MAC)D. Attribute-Based Access Control (ABAC)Answer: C​ Principle of least privilege:A. Giving users only necessary permissionsB. Allowing administrators unlimited accessC. Preventing user account creationD. Implementing mandatory security clearancesAnswer: A​ Time-based access control:A. Granted only during specific hoursB. Determined by user roleC. Restricted to known locationsD. Granted after authentication expiresAnswer: A​ Centralized server enforcing access control policies:A. FirewallB. Directory ServiceC. Proxy ServerD. Load BalancerAnswer: B​ Attack using stolen session token:A. Brute forceB. Replay attackC. Session hijackingD. PhishingAnswer: C​ Access control model where users can grant/restrict access:A. Discretionary Access Control (DAC)B. Mandatory Access Control (MAC)C. Role-Based Access Control (RBAC)D. Attribute-Based Access Control (ABAC)Answer: A​ Purpose of a password policy:A. Encrypt filesB. Enforce secure password creation/managementC. Monitor login attemptsD. Limit account creationAnswer: B​ “Something you have” in MFA:A. PasswordB. Smart cardC. BiometricsD. PINAnswer: B​ Risk of sharing user credentials:A. Loss of password integrityB. Violation of encryption standardsC. Increased bandwidth usageD. Unauthorized accessAnswer: D​ Purpose of account lockout policies:A. Block malicious trafficB. Prevent brute force attacksC. Encrypt sensitive dataD. Monitor login attemptsAnswer: B​ Access control dynamically adjusting access by location:A. Attribute-Based Access Control (ABAC)B. Role-Based Access Control (RBAC)C. Mandatory Access Control (MAC)D. Discretionary Access Control (DAC)Answer: A​ Primary purpose of biometric authentication:A. Enhance encryptionB. Verify physical characteristicsC. Monitor network trafficD. Backup critical dataAnswer: B​ Granting temporary access:A. Privilege escalationB. Time-bound accessC. User provisioningD. Conditional accessAnswer: B​ Attack manipulating users to share confidential data:A. MalwareB. Social engineeringC. PhishingD. KeyloggingAnswer: B​ Preventing password reuse:A. Multi-factor authenticationB. Password history policiesC. Single sign-onD. EncryptionAnswer: B​ Primary function of access control logs:A. Block unauthorized usersB. Record access attemptsC. Update user rolesD. Enforce encryptionAnswer: B​ Purpose of a firewall:A. Detect malwareB. Filter traffic between networksC. Encrypt sensitive informationD. Manage bandwidthAnswer: B​ Attack flooding a network to disrupt resources:A. Man-in-the-middleB. PhishingC. Denial of Service (DoS)D. ReplayAnswer: C

Episode metadata supplied by the publisher feed · Published Jan 21, 2025

Embed this episode

NOW PLAYING

ISC2 CC Domain 3: Access Control Study Exam Questions by Edward Henriquez

0:00 18:35

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Decoded: The Cybersecurity Podcast?

This episode is 18 minutes long.

When was this Decoded: The Cybersecurity Podcast episode published?

This episode was published on January 21, 2025.

Can I download this Decoded: The Cybersecurity Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!