Access Control Flashcards
(231 cards)
Is a passive entity (system or process) a subject or an object?
Object
Is an active entity (individual or process) a subject or object?
Subject
Which type of control is used to reduce risk?
Preventative, deterrent, corrective, recovery, detective, compensating, directive
Preventative
Which type of control identifies violations and incidents?
Preventative, corrective, detective, compensating, recovery, deterrent, directive
Detective
Which type of control is used for re mediating violations and incidents and improving preventative and detective controls?
(Preventative, detective, deterrent, corrective, compensating, recovery, directive)
Corrective
Which control is used for discouraging violations?
Preventative, corrective, deterrent, recovery, detective, compensating, directive
Deterrent
Which type of control is used for restoring systems and information?
(Preventative, detective, deterrent, corrective, recovery, compensating, directive)
Recovery
Which of these determines whether a subject can login?
Authentication, Authorisation, Accountability
authorisation
Which control provides alternative ways of achieving a task?
Preventative, corrective, recovery, compensating, detective, deterrent, directive
Compensating
Which of these determines what a subject can do? Ie access rights and permissions? (Authentication, authorisation, accountability)
Authorisation (or establishment)
What is non-repudiation?
It means that a user can’t deny an action because their identity is positively associated with their actions
Which of these determines what a subject did?
Authorisation, authentication, accountability
Accountability
For the CISSP exam is an ATM card considered 2FA?
Yes
How many characters does a password have to be for it not to be stored in AD or local SAM (Security Account Manager)?
15 or longer
Biometrics: what is a one to one search?
Identify matched against an image file
Biometrics: what is a one to many search?
Identity matched against a database of identities
Which type of authentication system is a false reject rate or type 1 error used?
Biometric system
Note for exam: is biometric authentication considered 2fa?
No
What is a false reject rate (FRR) or type 1 error?
The percentage of authorised users to whom a system incorrectly denies access
What is a false accept rate (far) or type 2 error?
The percentage of unauthorised users to whom the system incorrectly grants access
In biometrics what is the crossover error rate (CER)?
The point at which the false accept rate equals the false reject rate
Which of these is considered the most important in biometric system accuracy? (False accept rate, false reject rate, crossover error rate)
Crossover error rate
CISSP answer: what is the most common difficulty about implementing a biometric system?
User acceptance
Generally accepted standards for biometric systems Accuracy = Speed = Throughput = Enrolment time =
Accuracy = crossover error rate less than 10%
Speed = 5 seconds
Throughput = 6 to 10 per minute
Enrolment time = less than 2 mins