3.7 Given a Scenario, Implement Identity and Account Management Controls Flashcards

1
Q

IAM

A

Identity and access management is combination of authentication and authorization into a single solution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Identity implemented as a controls

A

Identity is the first step in AAA (authentication, authorization, accounting)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

IdP

A

Identity provider- is a system that manages and creates identities within a internal network, CSP, Directory, or third party.

Provides SSO solutions for intranet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Attributes in Identity control

A

Attributes are specific characteristic that belong to a entity (person, Corp, or business.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Certificates

A

mechanism for verifying the identity of devices, systems, services, applications, networks, and organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Tokens

A

a digital file that is issued to a person or device when successful log in.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SSH Keys

A

Used in a SSH session setup to identify the client.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Account Types

A

User Account
Shared Account
Guest Account
Service Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

User Account

A

User Account is a standard account that every user has.
Some User Accounts have more rights such as System Admin.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Shared Accounts

A

A public account such as a Kiosks that everyone has access too.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Guest Account

A

Guest Account are account that have very limited privileges.
Guest account should have some way to identify who the guest account be longs too.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Service Accounts

A

Service accounts are accounts that have very acute privileges for test a applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Account Polices

A

Polices that explain the security standard for organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Password Policy

A

Password policy enforces rules that a user follows when creating passwords. (Length, minimum, age, complexity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Password History in correlation to Policy

A

Previous passwords are archived so that the same password wont be used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Time-Based Logins

A

Logs out a user when time has expired on a user accounts.

17
Q

Access Polices

A

Defines what access is granted over a object or asset. Focuses on the users job description.

18
Q

Account Audits

A

Checking the activity of a account

19
Q

Disablement

A

Account Admin disables a account either by setting a expiration date or manually disabling it