111. Which of the following is critical to understanding an access control policy?
a.
Reachable-stateb.
Protection-statec.
User-stated.
System-state112. Which of the following should
a.
Data encryption standard (DES)b.
Advanced encryption standard (AES)c.
Rivest, Shamir, and Adelman (RSA)d.
Diffie-Hellman (DH)113. From an access control decision viewpoint, failures due to flaws in permission-based systems tend to do which of the following?
a.
Authorize permissible actionsb.
Fail-safe with permission deniedc.
Unauthorize prohibited actionsd.
Grant unauthorized permissions114. Host and application system hardening procedures are a part of which of the following?
a.
Directive controlsb.
Preventive controlsc.
Detective controlsd.
Corrective controlsDirective controls are broad-based controls to handle security incidents, and they include management’s policies, procedures, and directives. Detective controls enhance security by monitoring the effectiveness of preventive controls and by detecting security incidents where preventive controls were circumvented. Corrective controls are procedures to react to security incidents and to take remedial actions on a timely basis. Corrective controls require proper planning and preparation as they rely more on human judgment.
115. From an access control decision viewpoint, fail-safe defaults operate on which of the following?
1.
Exclude and deny2.
Permit and allow3.
No access, yes default4.
Yes access, yes defaulta.
1 onlyb.
2 onlyc.
2 and 3d.
4 only116. For password management, automatically generated random passwords usually provide which of the following?
1.
Greater entropy2.
Passwords that are hard for attackers to guess3.
Stronger passwords4.
Passwords that are hard for users to remembera.
2 onlyb.
2 and 3c.
2, 3, and 4d.
1, 2, 3, and 4117. In biometrics-based identification and authentication techniques, which of the following indicates that security is unacceptably weak?
a.
Low false acceptance rateb.
Low false rejection ratec.
High false acceptance rated.
High false rejection rate