Access Controls & Identity Management Flashcards
9 cards from real SSCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 9 Access Controls & Identity Management flashcards as text
What is the primary purpose of Role‑Based Access Control (RBAC)?
Answer: Assign permissions based on job functions
Role-Based Access Control (RBAC) is a security model that assigns permissions to users based on their specific job functions or roles within an organization. Instead of granting individual permissions, users inherit access rights defined for their role, simplifying management and enforcing the principle of least privilege.
In multi‑factor authentication, which factor is considered "something you are"?
Answer: Fingerprint scan
In multi-factor authentication, "something you are" refers to a biometric factor, which is a unique physical characteristic of an individual. A fingerprint scan falls into this category, providing a strong and personal method of identity verification beyond just passwords or tokens.
What does the principle of least privilege require in an IAM system?
Answer: Provide limited access needed for job duties
The principle of least privilege in an Identity and Access Management (IAM) system requires that users are granted only the minimum level of access necessary to perform their specific job duties. This minimizes the potential for unauthorized actions, accidental errors, or malicious activity, enhancing overall security.
Which protocol is commonly used for centralized authentication, authorization, and accounting in enterprise networks?
Answer: RADIUS
RADIUS (Remote Authentication Dial-In User Service) is a widely used networking protocol for centralized Authentication, Authorization, and Accounting (AAA) services in enterprise networks. It enables secure access to various network resources, such as Wi-Fi and VPNs, by verifying user identities and controlling their access privileges.
LDAP, used in many directory services, stands for ____.
Answer: Lightweight Directory Access Protocol
LDAP stands for Lightweight Directory Access Protocol. It is an open, industry-standard application protocol used for accessing and maintaining distributed directory information services, commonly employed for storing user and group information and facilitating authentication in many enterprise environments.
Which statement best describes Single Sign‑On (SSO)?
Answer: It lets users access several systems after one login
Single Sign-On (SSO) allows users to access multiple connected systems or applications after authenticating just once with a single set of credentials. This enhances user convenience by reducing the number of passwords to remember and improves security by centralizing authentication management.
What is the main security benefit of implementing account lockout policies?
Answer: Prevent brute‑force password attacks
Account lockout policies are a critical security measure designed to prevent brute-force password attacks. By temporarily disabling an account after a specified number of failed login attempts, these policies thwart attackers from repeatedly guessing passwords until they succeed, thus protecting user accounts.
Which policy ensures that no single individual has enough privileges to misuse the system?
Answer: Separation of Duties
The policy of Separation of Duties ensures that no single individual has enough privileges to misuse a system or complete a critical task alone. By dividing responsibilities among different people, it minimizes the risk of fraud, error, or unauthorized actions, enhancing internal controls and security.
How should unused or stale user accounts be handled to improve security?
Answer: Disable or delete them promptly
To improve security, unused or stale user accounts should be disabled or deleted promptly. These accounts pose a significant security risk as they can be exploited by attackers to gain unauthorized access, so removing them reduces the attack surface and adheres to the principle of least privilege.