A security engineer is designing a system that must ensure data integrity at all costs, even if it means sacrificing availability. Which access control model and corresponding principle should be applied?
A security auditor is reviewing the account lifecycle process. Which TWO of the following are mandatory steps during the deprovisioning (offboarding) process?
An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?
During a security audit, it is discovered that a service account has been used to log in interactively to a server. The account was originally provisioned only for running a background service. Which PAM (Privileged Access Management) control would best prevent such misuse in the future?
A security architect is designing an access control system for a healthcare application that requires fine-grained access decisions based on user role, location, time of day, and patient consent. Which TWO access control models are best suited for this requirement?
An organization uses Kerberos for single sign-on (SSO) within its Windows domain. Which component issues ticket-granting tickets (TGTs) after verifying user credentials?
A security administrator is configuring a system to enforce separation of duties. In which access control model is this principle most directly implemented?
A company wants to implement multi-factor authentication (MFA) for remote access. Which THREE of the following are examples of different authentication factors? (Choose THREE.)
A security analyst notices that a user's account was used to access sensitive files after the user had left the company. Which access control principle was most likely violated?
A security analyst is investigating an account compromise. The organization uses Kerberos for single sign-on. Which TWO of the following would help in tracking the source of the compromise?
A security engineer is designing a federated identity solution for cross-domain authentication. Which THREE of the following technologies are commonly used?
A security administrator is reviewing access logs and notices that a user was able to access a file after only providing a username and password, even though the file contains highly sensitive data. The organization's policy requires that access to sensitive files be based on the user's job role and that users should not have direct control over permissions. Which access control model is most likely in use, and what is the primary weakness?
A security administrator is designing an attribute-based access control (ABAC) policy for a cloud environment. The policy must evaluate multiple types of attributes to make access decisions. Which TWO of the following are categories of attributes that ABAC typically evaluates? (Choose two.)
An administrator is configuring a Linux server and wants file access to be governed by the permissions of the directory in which the file resides, rather than by the file's own permission bits. Which permission should the administrator apply to the directory to achieve this behavior?
A financial services firm runs a quarterly access review. The security team discovers that a payroll administrator can also approve vendor invoices in the ERP system, and that the same individual can modify their own expense reimbursements. The CISO asks which access control principle is being violated so it can be documented as a finding.
A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?
A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?
An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?
A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?
A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?
An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?
A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?
In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?
An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?
A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?
A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?
An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?
An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?
A company is implementing a biometric authentication system for physical access to a data center. The system must minimize false acceptances. Which metric is most directly related to false acceptance rate (FAR)?
A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?
An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?
A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?
A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)
A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)
A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?
In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?
In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?
An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?
During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?
An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?
An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?
An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?
An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?
A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?
An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)
An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?
An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?
An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?
A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?
A healthcare organization deploys a new electronic records system. Clinicians may access patient records only while assigned to the cardiology department, and access is automatically revoked when they rotate to oncology. Which access control model best supports this requirement?
A financial services firm wants to let customers authorize a third-party budgeting application to read their account transaction history without sharing their banking password. Which technology should the firm deploy?
A healthcare organization uses a mandatory access control (MAC) system to protect patient records. A nurse with a Secret clearance attempts to access a file classified as Top Secret. According to the Bell-LaPadula model, what will happen?
A financial institution uses a RADIUS server for centralized authentication of its VPN users. A security administrator notices that authentication requests from a new VPN concentrator are being rejected, while requests from other devices work fine. The RADIUS server logs show that the shared secret does not match. What is the most likely cause?
A security administrator is configuring a Linux server that hosts a shared project directory. The requirement is that new files created in the directory /projects/team must automatically inherit the group owner of the parent directory rather than the primary group of the user who created them. The administrator wants the setting to apply only to that directory. Which command should the administrator use?
A hospital is deploying a new electronic health records (EHR) system. The security team wants to ensure that access decisions are based on the user's assigned job function rather than on the user's identity or resource ownership. Which access control model best meets this requirement?
A company uses discretionary access control (DAC) for its file shares. A project manager creates a folder and wants to grant a team member read-only access. Which of the following best describes how access is determined in this model?
A security administrator at a financial firm is configuring access control for a new document management system. The system must enforce access decisions based on the sensitivity labels of documents and the clearance levels of employees, and it must prevent users from delegating their access to others. Which access control model should the administrator implement?
A security team is reviewing access control models for a new document management system. The system must support discretionary sharing where document owners can grant access to other users, but it must also enforce a mandatory rule that any document labeled 'Confidential' cannot be accessed by users without a 'Confidential' clearance, regardless of owner intent. Which access control model best satisfies both requirements?
A security administrator is configuring access controls for a shared file server. The administrator wants to grant permissions based on the sensitivity labels of the files and the clearance levels of the users, ensuring that users cannot change these permissions. Which access control model should be implemented?
A small business owner wants to implement access control for a shared folder on a Windows server. The owner wants to grant different permissions to individual employees based on their specific job duties, without creating groups. Which access control model is most appropriate?
A security team is designing an access control system for a research facility. They need a model that supports fine-grained, dynamic access decisions based on user department, project assignment, time of day, and the sensitivity of the resource. The model must also allow policies to be expressed in a human-readable language and evaluated at runtime. Which access control model best fits these requirements?
A security analyst is reviewing authentication logs and notices that a user account was used to log in from two different geographic locations within a five-minute window. The organization uses a centralized RADIUS server for authentication. Which of the following should the analyst investigate FIRST to determine if this is a legitimate concurrent session or a compromise?
A financial institution uses a centralized authentication system. An auditor notes that when an employee is terminated, their access to several critical applications remains active for up to 24 hours because each application maintains its own local user database. Which of the following is the MOST effective control to reduce this window of exposure?
A healthcare organization must enforce access control based on a combination of the user's assigned department, the classification of the data being accessed, and the time of day. Users in the cardiology department may view patient records only during their scheduled shift, and only if the record belongs to a patient currently admitted to cardiology. Which access control model BEST supports these requirements?
A hospital uses a MAC-based system where data labels carry classifications such as Restricted and Public, and user clearances are assigned by the security office. A nurse with a Secret-equivalent clearance attempts to read a patient record labeled with a higher classification. According to the Bell-LaPadula model, what should occur?
A security administrator is implementing a biometric access control system for a data center. The organization wants to minimize the chance that an unauthorized person is granted access, even if it means legitimate users occasionally have to retry. Which metric should the administrator tune to achieve this goal?
A small business wants employees to authenticate to the corporate VPN using a hardware token that generates a time-based one-time code in addition to their password. Which authentication factor category does the hardware token represent?
A company deploys a RADIUS server for wireless 802.1X authentication. Users report that after a password change, their devices still authenticate successfully for several hours using cached credentials. Which RADIUS behavior most likely explains this?
A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)
A security administrator is designing an access control scheme for a research lab where data sensitivity varies widely and the organization wants the operating system itself to enforce access decisions based on labels, independent of user discretion. Which TWO of the following characteristics apply to mandatory access control (MAC)? (Choose two.)
A hospital wants clinicians to reach patient records from any ward workstation without signing in repeatedly, but it also wants a single authoritative source of identity so that disabling an employee in the human resources system immediately removes clinical access. The identity team proposes using the Lightweight Directory Access Protocol (LDAP) as that authoritative store. Which statement best describes what LDAP provides in this design?
A company is implementing a new access control system and wants to ensure that users are granted only the minimum permissions necessary to perform their job functions. Which principle is being applied?
A security auditor is evaluating a company's implementation of mandatory access control (MAC) using a commercial trusted operating system. The auditor needs to verify that the MAC implementation correctly enforces the no read up and no write down rules for confidentiality. Which TWO of the following are essential characteristics the auditor should confirm? (Choose two.)
A small business wants to implement single sign-on so employees can authenticate once and reach several internal web applications without re-entering credentials. The applications support SAML 2.0. Which component issues the signed assertion that the applications consume to establish the user's identity?
A small business owner wants to implement access control for a shared file server. The owner wants each department manager to be able to decide which of their employees can access specific folders, without involving the IT department for every change. Which access control model is most appropriate for this requirement?
A security team is hardening a centralized authentication service and wants to reduce the risk of credential replay and lateral movement if a password is compromised. Which TWO of the following controls directly support this goal? (Choose two.)
A retail chain issues each cashier a badge containing a photograph and a scannable code. At the start of every shift, a supervisor visually compares the badge photograph to the person and scans the code into the point-of-sale terminal. Which two access control components are being combined in this process?
A financial services firm is deploying a centralized access control server that will make authorization decisions for dozens of internal applications. The architects want the applications to query a single decision point instead of embedding their own permission logic. Which two characteristics should the chosen model exhibit? (Choose two.)
A financial firm is designing access controls for a trading application. The firm wants to prevent any single employee from both initiating a large funds transfer and approving it, and it also wants to ensure that access rights are automatically revoked when an employee changes departments. Which combination of principles is the firm applying?
A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?
A defense contractor runs an air-gapped laboratory where removable media are used to move engineering data between isolated enclaves. Policy requires that a workstation be usable only when a specific approved removable device is inserted, and that the workstation become unusable the instant that device is removed. Which access control approach best enforces this behavior?
A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)
A retail company issues contactless smart cards to employees for physical entry to its data center. The security manager wants to ensure that a lost card cannot be used by someone who finds it, without adding a fingerprint reader at every door. Which access control enhancement best meets this requirement?
A software company wants outside contractors to reach a single internal source code repository without creating accounts in the company directory. The identity team proposes using the Security Assertion Markup Language so that contractors authenticate against their own employer's identity provider. Which statement describes the trust relationship that must exist for this to work?