Добавил:
Я за два дня прошел весь курс ТВиМС Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
!ОСНОВНАЯ КНИГА КУРСА! Chapple M. (ISC)2 CISSP Certified IS...Study Guide 9ed 2021.pdf
Скачиваний:
0
Добавлен:
20.06.2025
Размер:
15.75 Mб
Скачать

718Chapter 14  Controlling and Monitoring Access

Review Questions

1.Which of the following best describes an implicit deny principle?

A.All actions that are not expressly denied are allowed.

B.All actions that are not expressly allowed are denied.

C.All actions must be expressly denied.

D.None of the above.

2.A table includes multiple objects and subjects, and it identifies the specific access each subject has to different objects. What is this table?

A.Access control list

B.Access control matrix

C.Federation

D.Creeping privilege

3.You are reviewing access control models and want to implement a model that allows the owner of an object to grant privileges to other users. Which of the following meets this requirement?

A.Mandatory Access Control (MAC) model

B.Discretionary Access Control (DAC) model

C.Role-­Based Access Control (RBAC) model

D.Rule-­based access control model

4.Which of the following access control models allows the owner of data to modify permissions?

A.Discretionary Access Control (DAC)

B.Mandatory Access Control (MAC)

C.Rule-­based access control

D.Risk-­based access control

5.A central authority determines which files a user can access based on the organization’s hierarchy. Which of the following best describes this?

A.DAC model

B.An access control list (ACL)

C.Rule-­based access control model

D.RBAC model

6.Which of the following statements is true related to the RBAC model?

A.A RBAC model allows users membership in multiple groups.

B.A RBAC model allows users membership in a single group.

Review Questions

719

C.A RBAC model is nonhierarchical.

D.A RBAC model uses labels.

7.You are reviewing different access control models. Which of the following best describes a rule-­based access control model?

A.It uses local rules applied to users individually.

B.It uses global rules applied to users individually.

C.It uses local rules applied to all users equally.

D.It uses global rules applied to all users equally.

8.Your organization is considering deploying a software-­defined network (SDN) in the data center. Which of the following access control models is commonly used in a SDN?

A.Mandatory Access Control (MAC) model

B.Attribute-­Based Access Control (ABAC) model

C.Role-­Based Access Control (RBAC) model

D.Discretionary Access Control (DAC) model

9.The MAC model supports different environment types. Which of the following grants users access using predefined labels for specific labels?

A.Compartmentalized environment

B.Hierarchical environment

C.Centralized environment

D.Hybrid environment

10.Which of the following access control models identifies the upper and lower bounds of access for subjects with labels?

A.Nondiscretionary access control

B.Mandatory Access Control (MAC)

C.Discretionary Access Control (DAC)

D.Attribute-­Based Access Control (ABAC)

11.Which of the following access control models uses labels and is commonly referred to as a lattice-based model?

A.DAC

B.Nondiscretionary

C.MAC

D.RBAC

12.Management wants users to use multifactor authentication any time they access cloud-­based resources. Which of the following access control models can meet this requirement?

A.Risk-­based access control

B.Mandatory Access Control (MAC)

720Chapter 14  Controlling and Monitoring Access

C.Role-­Based Access Control (RBAC)

D.Discretionary Access Control (DAC)

13.Which of the following access control models determines access based on the environment and the situation?

A.Risk-­based access control

B.Mandatory Access Control (MAC)

C.Role-­Based Access Control (RBAC)

D.Attribute-­Based Access Control (ABAC)

14.A cloud-­based provider has implemented an SSO technology using JSON Web Tokens. The tokens provide authentication information and include user profiles. Which of the following best identifies this technology?

A.OIDC

B.OAuth

C.SAML

D.OpenID

15.Some users in your network are having problems authenticating with a Kerberos server. While troubleshooting the problem, you verified you can log on to your regular work computer. However, you are unable to log on to the user’s computer with your credentials. Which of the following is most likely to solve this problem?

A.Advanced Encryption Standard (AES)

B.Network Access Control (NAC)

C.Security Assertion Markup Language (SAML)

D.Network Time Protocol (NTP)

16.Your organization has a large network supporting thousands of employees, and it utilizes Kerberos. Of the following choices, what is the primary purpose of Kerberos?

A.Confidentiality

B.Integrity

C.Authentication

D.Accountability

17.What is the function of the network access server within a RADIUS architecture?

A.Authentication server

B.Client

C.AAA server

D.Firewall

Review Questions

721

18.Larry manages a Linux server. Occasionally, he needs to run commands that require root-­ level privileges. Management wants to ensure that an attacker cannot run these commands if the attacker compromises Larry’s account. Which of the following is the best choice?

A.Grant Larry sudo access.

B.Give Larry the root password.

C.Add Larry’s account to the administrator’s group.

D.Add Larry’s account to the LocalSystem account.

19.An attacker used a tool to exploit a weakness in NTLM. They identified an administrator’s user account. Although the attacker didn’t discover the administrator’s password, they did access remote systems by impersonating the administrator. Which of the following best identifies this attack?

A.Pass the ticket

B.Golden ticket

C.Rainbow table

D.Pass the hash

20.Your organization recently suffered a major data breach. After an investigation, security analysts discovered that attackers were using golden tickets to access network resources. Which of the following did the attackers exploit?

A.RADIUS

B.SAML

C.Kerberos

D.OIDC

Chapter

15

Security Assessment

and Testing

THE CISSP EXAMTOPICS COVERED INTHIS CHAPTER INCLUDE:

Domain 6.0: Security Assessment and Testing

■■6.1 Design and validate assessment, test, and audit strategies

■■6.1.1 Internal

■■6.1.2 External

■■6.1.3Third-party

■■6.2. Conduct security control testing

■■6.2.1 Vulnerability assessment

■■6.2.2 Penetration testing

■■6.2.3 Log reviews

■■6.2.4 Synthetic transactions

■■6.2.5 Code review and testing

■■6.2.6 Misuse case testing

■■6.2.7Test coverage analysis

■■6.2.8 Interface testing

■■6.2.9 Breach attack simulations

■■6.2.10 Compliance checks

■■6.3 Collect security process data (e.g., technical and administrative)

■■6.3.1 Account management

■■6.3.2 Management review and approval

■■6.3.3 Key performance and risk indicators

■■6.3.4 Backup verification data

■■6.3.5Training and awareness

■■6.4 Analyze test output and generate report

■■6.4.1 Remediation

■■6.4.2 Exception handling

■■6.4.3 Ethical disclosure

■■6.5 Conduct or facilitate security audits

■■6.5.1 Internal

■■6.5.2 External

■■6.5.3Third-party

Domain 8.0: Software Development Security

■■8.2 Identify and apply security controls in software development ecosystems

■■8.2.10 Application security testing (e.g., Static Application SecurityTesting (SAST), Dynamic Application SecurityTesting (DAST))

Соседние файлы в предмете Информационная безопасность автоматизированных систем