Courseiva

CCNA Access Control and Password Management Questions

13 questions · Access Control and Password Management · All types, answers revealed

1
MCQmedium

A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?

A.Enforce password history
B.Minimum password age
C.Password must meet complexity requirements
D.Maximum password age
AnswerA

Enforce password history determines how many unique new passwords must be used before an old password can be reused. Setting it to 24 prevents reuse of the last 24 passwords, directly meeting the requirement. This is the correct setting because it specifically tracks and blocks previous password hashes, ensuring users cannot cycle back to recent passwords.

Why this answer

The Enforce password history policy setting in Active Directory allows administrators to specify the number of previous passwords that cannot be reused. Setting it to 24 ensures users must choose 24 unique passwords before they can reuse an old one. This directly addresses the requirement to prevent reuse of the last 24 passwords.

Other settings like maximum age, minimum age, or complexity do not track password reuse and therefore do not meet the stated goal.

Exam trap

The trap here is confusing password history with password complexity or age policies, which do not prevent reuse of previous passwords.

2
MCQeasy

Which of the following describes the 'Principle of Least Privilege' in an access control context?

A.Granting all employees access to the root directory for troubleshooting
B.Providing users only the access required to complete their tasks
C.Using the same shared password for all administrative accounts
D.Ensuring all users have administrator rights for software updates
AnswerB

This definition aligns perfectly with the Principle of Least Privilege. By restricting access to only what is strictly necessary, an organization significantly reduces the impact of accidental mistakes, insider threats, and external attacks, as an attacker will find themselves limited by the restricted permissions of the compromised account.

Why this answer

The Principle of Least Privilege (PoLP) mandates that users should only be granted the minimum level of access necessary to perform their job functions. This minimizes the attack surface; if a user account is compromised, the potential damage is restricted to the limited permissions assigned to that account. This is a fundamental security concept for preventing lateral movement and privilege escalation during an active incident or breach.

Exam trap

Candidates often confuse the Principle of Least Privilege with 'Need to Know' or general access control policies, failing to recognize that PoLP specifically mandates the minimum permissions required for task completion.

3
MCQeasy

What is the primary purpose of Salt in password hashing?

A.To shorten the length of the stored hash
B.To prevent the use of rainbow tables
C.To increase the complexity of the user's password
D.To facilitate easier password recovery
AnswerB

Rainbow tables are pre-computed tables of hashes used to crack passwords quickly. By using a unique salt for every user, the set of possible hashes becomes effectively infinite for any given password, rendering rainbow tables useless because they cannot account for the random salt value injected into the hash function.

Why this answer

A salt is a unique, random string added to a password before it is hashed. This ensures that even if two users have the same password, their resulting hashes will be different. This prevents attackers from using pre-computed tables, such as rainbow tables, to quickly reverse the hashes of stolen passwords.

By forcing attackers to calculate hashes for each individual user, the salt significantly increases the computational cost of brute-force and dictionary attacks.

Exam trap

Examinees often confuse salts with pepper or general key stretching functions, incorrectly believing that the primary goal is simply to slow down brute-force guessing rather than neutralizing pre-computed lookup tables.

4
MCQhard

A security administrator is hardening authentication on a set of Linux servers that will be accessed by third-party contractors. Management requires that contractors authenticate with a one-time code delivered by a hardware token, while local administrators continue to use their existing passwords, and that both methods can be used on the same SSH service without changing the client software. Which approach best meets these requirements?

A.Deploy RADIUS backed by a token server, point sshd at PAM's pam_radius_auth.so, and let the RADIUS policy assign token authentication to contractor accounts and password authentication to administrator accounts.
B.Configure PAM to stack pam_unix.so and pam_google_authenticator.so with the requisite control flag in /etc/pam.d/sshd so both factors are required for every account.
C.Set PasswordAuthentication to no and ChallengeResponseAuthentication to yes in sshd_config, then distribute hardware tokens to all accounts so every user supplies a one-time code.
D.Issue each contractor an SSH certificate signed by an internal CA and configure sshd with TrustedUserCAKeys, leaving administrator accounts on password authentication.
AnswerA

RADIUS centralizes the decision of which authentication method each account must satisfy. Contractors are mapped to token-based policies while administrators retain password authentication, and because sshd still calls PAM, the existing SSH clients need no changes. This satisfies every constraint in the scenario without duplicating credentials locally.

Why this answer

The requirement is per-account, per-method authentication on a shared SSH service with no client changes. A RADIUS-backed token server reached through PAM lets the authentication policy decide which accounts need a hardware token and which may use a password, while sshd continues to use its normal PAM stack. This preserves existing clients and separates the two populations cleanly, matching every stated constraint.

Exam trap

The trap here is assuming that stacking every PAM module with a requisite flag automatically satisfies mixed authentication requirements, when it actually forces all factors on all accounts.

5
Multi-Selectmedium

A security team is implementing a new access control system for a research lab. They need to ensure that access decisions are based on the user's role and the sensitivity of the resource, and that users are only granted the minimum permissions necessary to perform their job. Which two access control principles should they apply? (Choose two.)

Select 2 answers
A.Discretionary Access Control (DAC)
B.Rule-Based Access Control
C.Principle of Least Privilege
D.Mandatory Access Control (MAC)
E.Role-Based Access Control (RBAC)
AnswersC, E

The principle of least privilege states that users should be granted only the minimum access rights required to perform their job functions. This directly matches the requirement to grant minimum permissions necessary. Applying this principle reduces the attack surface and limits potential damage from compromised accounts, making it a core component of the desired access control system.

Why this answer

Role-Based Access Control (RBAC) bases access decisions on the user's role, and the principle of least privilege ensures users only have the minimum permissions needed. Together, they meet the requirement to use role and resource sensitivity while enforcing least privilege. DAC, MAC, and rule-based access control do not specifically combine role-based decisions with least privilege in the same way.

Exam trap

The trap here is selecting MAC or DAC because they sound strict or familiar, but they do not directly address role-based decisions and least privilege as required.

6
MCQeasy

A security analyst is reviewing authentication logs and notices that an attacker attempted to log in using a list of previously breached username and password combinations. The attack failed because the organization had implemented a control that requires users to provide a second factor in addition to their password. Which type of attack was mitigated?

A.Rainbow table attack
B.Credential stuffing
C.Brute force
D.Password spraying
AnswerB

Credential stuffing uses lists of username and password pairs obtained from data breaches on other sites. Attackers assume users reuse credentials across services. The scenario explicitly mentions a list of previously breached combinations, which is the hallmark of credential stuffing. Requiring a second factor (like a one-time code) prevents unauthorized access even if the password is correct, effectively mitigating this attack.

Why this answer

Credential stuffing specifically uses breached username and password pairs to gain unauthorized access. The presence of a second authentication factor prevents the attacker from succeeding even with valid credentials. Other attacks like password spraying, brute force, or rainbow tables do not rely on breached credential lists in the same way.

Therefore, the mitigated attack is credential stuffing.

Exam trap

The trap here is confusing credential stuffing with password spraying, as both involve multiple login attempts, but credential stuffing uniquely uses breached credentials from other services.

7
MCQhard

A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?

A.Credential stuffing
B.Pass-the-hash
C.Man-in-the-middle attack
D.Brute-force attack
AnswerC

A man-in-the-middle attack can intercept the authentication session and relay the one-time code in real time. If the attacker positions themselves between the user and the VPN, they can capture the password and the token code as the user submits them, then use them to authenticate before the code expires. This allows bypassing the hardware token requirement without possessing the physical token.

Why this answer

A man-in-the-middle attack allows an attacker to intercept and relay authentication credentials, including one-time codes, in real time. If the attacker can position themselves between the user and the VPN, they can capture both the password and the token code as they are transmitted. The attacker then uses these to authenticate before the code expires, effectively bypassing the need to physically possess the hardware token.

Other attacks like pass-the-hash, credential stuffing, or brute-force do not provide the one-time code.

Exam trap

The trap here is assuming that a hardware token makes authentication immune to interception, forgetting that real-time relay attacks can capture and reuse one-time codes.

8
MCQmedium

An organization is deploying a new VPN solution and wants to ensure that authentication credentials are not transmitted in cleartext over the internet. The security team decides to use a protocol that encapsulates authentication within a TLS tunnel. Which protocol should they implement?

A.EAP-TTLS
B.CHAP
C.PAP
D.MS-CHAPv2
AnswerA

EAP-TTLS (Extensible Authentication Protocol - Tunneled Transport Layer Security) establishes a TLS tunnel and then authenticates the client using various methods inside that tunnel. This ensures credentials are never sent in cleartext. It is commonly used in VPN and Wi-Fi authentication. The scenario requires encapsulating authentication within a TLS tunnel, which EAP-TTLS does by design, making it the correct choice.

Why this answer

EAP-TTLS encapsulates authentication within a TLS tunnel, protecting credentials from eavesdropping. PAP sends cleartext, CHAP uses a non-TLS challenge-response, and MS-CHAPv2 lacks TLS encapsulation. Only EAP-TTLS meets the requirement of transmitting authentication securely within a TLS tunnel, making it the correct protocol for the VPN deployment.

Exam trap

The trap here is assuming that any challenge-response protocol like CHAP or MS-CHAPv2 provides sufficient security, when they do not encapsulate authentication within TLS and remain vulnerable to offline attacks.

9
MCQmedium

Which password management practice best minimizes the impact of a credential stuffing attack?

A.Mandating password changes every 30 days
B.Requiring a minimum password length of 8 characters
C.Enforcing unique passwords per service
D.Disabling account lockout after failed attempts
AnswerC

Unique passwords ensure that even if one account's credentials are breached in a data leak, the attacker cannot use those same credentials to access other platforms. This containment strategy isolates the impact of a breach and prevents the automated success typically associated with large-scale credential stuffing campaigns against modern web services.

Why this answer

Credential stuffing relies on users reusing the same passwords across multiple services. By enforcing unique, complex passwords for every single account, users ensure that a compromise at one service does not lead to a cascade of compromises elsewhere. This is the single most effective defense against automated attacks that attempt to use leaked database dumps to gain unauthorized access to other unrelated accounts held by the same user.

Exam trap

Candidates often select 'frequent password changes' as the answer, failing to realize that frequent changes do not prevent credential stuffing if the same password is used everywhere.

10
MCQmedium

A security administrator is configuring a Linux server and needs to enforce that all user passwords are hashed with a strong, salted algorithm. Which file should the administrator edit to set the default password hashing algorithm for new passwords?

A./etc/pam.d/common-password
B./etc/passwd
C./etc/shadow
D./etc/login.defs
AnswerD

/etc/login.defs contains configuration settings for the shadow password suite, including the ENCRYPT_METHOD variable, which defines the default password hashing algorithm (e.g., SHA512). Editing this file allows the administrator to enforce a strong, salted algorithm for new passwords. This is the correct file because it controls system-wide password policy defaults.

Why this answer

The /etc/login.defs file contains the ENCRYPT_METHOD setting, which specifies the default password hashing algorithm for new passwords on many Linux distributions. Editing this file allows the administrator to enforce a strong, salted algorithm like SHA512. While /etc/shadow stores hashes and PAM configures authentication, the default algorithm is set in login.defs.

Therefore, this is the correct file to edit.

Exam trap

The trap here is assuming that the password hash file (/etc/shadow) or PAM configuration is where the default algorithm is set, when it is actually in /etc/login.defs.

11
MCQhard

A security administrator is reviewing the password policy for a high-security environment. The policy requires the use of a hardware token that generates a one-time password (OTP) based on a secret key and the current time. The administrator notices that some tokens are failing authentication because the server and tokens are not time-synchronized. Which of the following should the administrator implement to ensure the OTPs are validated correctly?

A.Enable NTP synchronization on the authentication server only.
B.Switch from time-based to event-based OTP tokens.
C.Increase the OTP length to 8 digits.
D.Configure a time drift window on the authentication server.
AnswerD

Time-based one-time password (TOTP) algorithms rely on synchronized clocks. If the token's clock drifts, the generated OTP will not match the server's expected value. Configuring a time drift window allows the server to accept OTPs from a few time steps before or after the current time, compensating for minor clock differences. This directly resolves the synchronization failures.

Why this answer

Time-based OTP tokens require the server and token to have closely synchronized clocks. When tokens drift, the server can accept OTPs from adjacent time steps by configuring a time drift window. This is a standard feature in TOTP implementations and directly addresses the authentication failures without replacing hardware or altering token generation.

Exam trap

The trap here is assuming that server-side NTP synchronization alone will fix token drift, when the tokens themselves cannot be synchronized and require a tolerance window.

12
Multi-Selecthard

A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)

Select 2 answers
A.Role-Based Access Control (RBAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Policy-Based Access Control (PBAC)
E.Attribute-Based Access Control (ABAC)
AnswersD, E

PBAC uses policies that can incorporate a wide range of attributes and conditions, including environmental factors. It centralizes policy management and enables dynamic, fine-grained access decisions. Often considered an evolution of ABAC, PBAC explicitly emphasizes policy-driven evaluation. It fits the requirement for centralized policy management and auditing, and supports context-aware decisions such as time-of-day restrictions.

Why this answer

Attribute-Based Access Control and Policy-Based Access Control both support dynamic, fine-grained access decisions using attributes and environmental conditions. They allow centralized policy management and auditing, which are critical for the financial institution. RBAC, MAC, and DAC lack the necessary flexibility and context-awareness.

Therefore, ABAC and PBAC are the correct choices.

Exam trap

The trap here is conflating RBAC with ABAC, assuming that role assignments alone can incorporate environmental conditions like time of day, which they cannot without additional attribute-based logic.

13
MCQhard

A security engineer is designing a password hashing scheme for a new application. The scheme must be resistant to GPU-accelerated cracking and allow for tuning of CPU and memory costs. Which hashing algorithm should the engineer choose?

A.Argon2
B.PBKDF2
C.bcrypt
D.SHA-256 with a random salt
AnswerA

Argon2 is the winner of the Password Hashing Competition and is designed to resist GPU cracking. It allows tuning of time cost (CPU), memory cost, and parallelism. This makes it highly adaptable to different hardware and security requirements. The scenario explicitly requires tuning of CPU and memory costs and resistance to GPU attacks, which Argon2 delivers. It is the recommended choice for new applications.

Why this answer

Argon2 is specifically designed to be memory-hard and CPU-hard, with tunable parameters for time, memory, and parallelism. This makes it resistant to GPU-accelerated cracking and allows customization for different environments. bcrypt and PBKDF2 lack memory tuning, and SHA-256 is too fast. Therefore, Argon2 is the correct choice for the password hashing scheme.

Exam trap

The trap here is assuming that any slow hashing algorithm like bcrypt or PBKDF2 is sufficient, overlooking the specific requirement for tunable memory costs that only Argon2 provides.

Ready to test yourself?

Try a timed practice session using only Access Control and Password Management questions.