access control Flashcards

(23 cards)

1
Q

Verifies who you ARE

A

authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

decides what youre ALLOWED to do

A

Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AuthN

A

Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AuthZ

A

Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

system-enforced rules

A

Mandatory Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Users cannot change permissions

A

Mandatory Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Military systems

A

Mandatory Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Strict, centralized control

A

Mandatory Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Owner controls access

A

Discretionary Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Users can grant/revoke permissions

A

Discretionary Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

File sharing with a friend

A

Discretionary Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Flexible but less secure

A

Discretionary Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

access based on roles

A

Role-based Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Admin > full access
Manager > limited
Employee > basic

A

RBAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Assign permissions to roles, not individuals

A

RBAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

access based on attributes

A

Attribute-based Access Control

17
Q

User (department, role)
Resource (type, sensitivity)
ENvironment (time, location)

18
Q

very flexible, policy-based

19
Q

Allow access only if:
user = HR
time = working hours
location = office network

20
Q

Controls who gets what level of access

A

Privilege Management

21
Q

Users get only what they need, nothing more

A

Least Privilege

22
Q

Why is Privilege Management important

A

reduces risk of misuse or attacks

23
Q

using physical or behavioral traits to verify identity