4.1 Compare and contrast identity and access management concepts Flashcards

1
Q

Identification, authentication, authorization, and accounting (AAA)

A

Identification—you need to ensure that customers are legitimate.

Authentication—you need to ensure that customers have unique accounts and that only they can manage their orders and billing information.

Authorization—you need rules to ensure customers can only place orders when they have valid payment mechanisms in place.

Accounting—the system must record the actions a customer takes (to ensure that they cannot deny placing an order, for instance).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Something you are

A

Employs some sort of biometric recognition system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Something you have

A

Examples include a smart card, USB token, or key fob that contains a chip with authentication data, such as a digital certificate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Something you know

A

The logon: this comprises a username and a password.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Somewhere you are

A

Location-based authentication measures some statistic about where you are. This could be a geographic location, measured using a device’s location service and the GPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Something you do

A

Refers to behavioral biometric recognition. Rather than scan some attribute of your body, a template is created by analyzing a behavior, such as typing or writing a signature.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Transitive trust

A

Trust extends to other trusted domains. For example, if Domain A trusts Domain B, and Domain B trusts Domain C, then Domain A also trusts Domain C.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Federation

A

The notion that a network needs to be accessible to more than just a well-defined group, such as employees.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Single Sign-on

A

Means that a user only has to authenticate to a system once to gain access to all the resources to which the user’s account has been granted rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly