Chapter 4.4 Flashcards

1
Q

AGDLP

A

Microsoft’s rule, “Accounts go into Global groups, which go into Domain Local groups, which get Permissions” (AGDLP) applies. This system provides a framework for placing users into Global groups based on their roles, then those groups are assigned to domain local groups (which have local resource permissions). This model is scalable and secure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does general account prohibition add a layer of safety to an Operating System (OS)?

A

Default administrator accounts should be disabled after being used to install the Operating System (OS). Systems administrators should have separate accounts for conducting administrative actions. This system helps protect against compromise of administrative accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

workflow

A

A workflow is an onboarding process that involves identifying the roles and permissions users need. A workflow is often a visual representation of an organization, organized by permissions and account types.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

offboarding

A

Offboarding is the process by which accounts are deleted or disabled. When personnel no longer need access to specific resources, permissions are withdrawn.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

UAC

A

User Account Control (UAC) is a Windows-specific function that prevents users from invoking administrative privileges without specific authorization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Privilege Bracketing

A

is an account management practice that involves giving users permissions to a resource for the duration of a specific project or need to know situation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In Windows Active Directory, how do Organizational Units (OUs) help account managers designate permissions?

A

OUs divide a domain into different administrative realms, which allows the domain administrator or account manager to delegate responsibility within different parts of the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly