Courseiva

CCNA Access Controls Concepts Questions

75 of 146 questions · Page 1/2 · Access Controls Concepts · Answers revealed

1
MCQmedium

Which of the following is the primary purpose of a visitor log and escort policy?

A.To enforce least privilege for employees
B.To provide a record of visitor access and ensure they are supervised
C.To authenticate visitors using biometrics
D.To prevent visitors from accessing the internet
AnswerB

A visitor log creates an auditable record of who entered, when and whom they visited, while escort requirements ensure visitors remain supervised and cannot wander into restricted areas. Together these satisfy the physical-security need for accountability and containment of unvetted individuals on site.

Why this answer

Option B is correct because the primary purpose of a visitor log and escort policy is to maintain a record of who enters a facility and when, and to ensure that visitors are supervised by authorized personnel while on-site. This supports physical security by preventing unauthorized access, enabling accountability, and ensuring that visitors do not wander into restricted areas without an escort.

Exam trap

The trap here is confusing logical access controls (least privilege, biometrics) with physical security controls — candidates may pick 'least privilege' because it sounds security-related, but the question specifically asks about visitor logs and escort policies, which are physical controls.

How to eliminate wrong answers

Option A is wrong because least privilege for employees is enforced through access control policies (e.g., role-based access, least privilege principles) for systems and data, not through visitor logs. Option C is wrong because biometric authentication is a specific access control mechanism, not the primary purpose of a visitor log and escort policy; visitor logs can be paper-based and do not require biometrics. Option D is wrong because preventing visitors from accessing the internet is not a standard goal of visitor management; the focus is on physical access control and supervision.

2
MCQeasy

A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?

A.Least privilege
B.Separation of duties
C.Need-to-know
D.Defense in depth
AnswerA

Least privilege grants each user only the permissions their role requires, nothing more. It satisfies the scenario's constraint by minimising the new employee's access rights, thereby limiting the damage any compromised or misused account could cause across systems.

Why this answer

The principle of least privilege states that a user should be granted only the minimum permissions necessary to perform their job duties. This limits the potential damage from accidents, errors, or malicious activity by ensuring users cannot access resources beyond their scope of work. It is a foundational security principle applied across systems, including access rights for new employees.

Exam trap

The trap here is confusing least privilege with need-to-know or separation of duties, which are related but distinct concepts; the question specifically asks about minimum permissions for job duties.

How to eliminate wrong answers

Option B is wrong because separation of duties divides critical tasks among multiple people to prevent fraud, rather than limiting a single user's permissions to the minimum. Option C is wrong because need-to-know is about restricting access to information based on whether the user requires it for a specific task, which is a subset of least privilege but not the overarching principle described. Option D is wrong because defense in depth is a layered security strategy using multiple controls, not the principle of granting minimal permissions.

3
MCQhard

A software company allows developers to access production servers only during an approved change window, and only after a manager approves a request that includes a ticket number and expiration time. Access is automatically revoked when the window closes. Which access control approach is being used?

A.Just-in-time (JIT) privileged access
B.Rule-based access control
C.Separation of duties
D.Time-of-day restriction
AnswerA

JIT privileged access grants elevated rights only for a limited period after an approved request, then automatically removes them. The scenario shows exactly this: manager approval, a ticket number, a defined change window, and automatic revocation when the window closes. This minimizes standing privileged access, reducing the attack surface compared with permanently assigned administrator rights.

Why this answer

The company grants elevated production access only after approval and only for a defined window, then revokes it automatically. That is just-in-time privileged access, which eliminates standing administrator rights and limits exposure to the change window. Time restrictions and approvals are components of the model, but the defining characteristic is temporary, request-driven elevation with automatic expiry.

Exam trap

The trap here is stopping at the time window and choosing a scheduling restriction, missing that approval workflow and automatic revocation make this a just-in-time elevation model.

4
MCQeasy

A hospital's IT department issues every nurse a unique smart card that must be inserted into a workstation before the nurse types a password. The smart card alone does not grant access to patient records. Which access control concept does the smart card insertion represent?

A.Identification
B.Authentication
C.Accounting
D.Authorization
AnswerA

Identification is the act of claiming an identity to a system, and the smart card presents a unique credential that tells the workstation who the nurse claims to be. Because the card by itself does not grant access and a password must still follow, it functions as the identification step that precedes authentication in the access control process.

Why this answer

The smart card presents a unique token that asserts who the nurse claims to be, which is the definition of identification. Because the card alone does not grant access and a password must still be supplied, verification of that claim is handled separately by authentication. Authorization and accounting occur only after identity is established and verified.

Exam trap

The trap here is assuming that possessing a physical token automatically verifies identity, when presenting it only claims an identity that still requires separate verification.

5
MCQmedium

A security analyst reviews server logs and sees that a single service account performed a login from an office workstation at 09:00 and then, two minutes later, executed administrative commands from an external IP address in another country. The account's password is long and complex. Which access control weakness does this pattern most likely indicate?

A.The account lockout threshold is set too high, allowing unlimited authentication attempts
B.The password policy permits weak passwords that are easily guessed
C.The account is not subject to least privilege, so it holds excessive administrative rights
D.The account lacks multifactor authentication, so stolen credentials can be reused from anywhere
AnswerD

Impossible-travel logins from two distant locations within minutes strongly suggest the credentials were captured and reused by an attacker. A long complex password offers no protection once it is stolen, but requiring a second factor such as a hardware token or authenticator app would have blocked the external session. The absence of MFA is the weakness that allows credential replay.

Why this answer

Two successful logins from geographically impossible locations within minutes indicate the credentials were stolen and reused. A long complex password cannot help once it is captured, but adding multifactor authentication means the attacker also needs the second factor, which blocks simple credential replay and is the control missing from this account.

Exam trap

The trap here is blaming password strength for a compromise when the credentials were valid and reused, which only multifactor authentication would have stopped.

6
Multi-Selecthard

According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)

Select 3 answers
A.Allow users to paste passwords to facilitate password manager use
B.Check passwords against known breached password lists
C.Require complex combinations of uppercase, lowercase, numbers, and symbols
D.Require frequent password changes every 30 days
E.Require a minimum length of 8 characters for most accounts
AnswersA, B, E

Allowing paste supports password managers, which NIST SP 800-63B explicitly endorses to reduce reuse and enable longer, higher-entropy secrets. Blocking paste forces weaker, memorable passwords and encourages poor workarounds. This satisfies the stem's recommendation for verifier practices that accommodate credential managers rather than impede them.

Why this answer

Option A is correct because NIST SP 800-63B explicitly recommends permitting "paste" functionality in password fields so that users can employ password managers, which generate and store strong, unique credentials. Option B is correct because the guideline requires verifiers to compare prospective passwords against lists of commonly used, expected, or compromised passwords (e.g., breach corpora) and reject matches. Option E is correct because NIST sets a minimum password length of 8 characters for user-chosen secrets, while encouraging longer passphrases (up to at least 64 characters).

Option C is not recommended because NIST advises against composition rules mandating mixed uppercase, lowercase, digits, and symbols, since they push users toward predictable patterns. Option D is not recommended because NIST discourages forced periodic rotation (e.g., every 30 days) absent evidence of compromise, as it weakens password quality.

Exam trap

The CC exam often tests the outdated belief that complex passwords and frequent changes are recommended, while NIST now advises against them in favor of length and breach checks.

7
MCQmedium

According to NIST SP 800-63, which password policy is most recommended?

A.Allow short passwords but require numbers and symbols
B.Use complex passwords with special characters and minimal length
C.Enforce a minimum length of 8 characters and check against breached password lists
D.Require frequent password changes every 30 days
AnswerC

NIST SP 800-63B advises against composition and rotation rules, favouring length and blocklist screening. An eight-character minimum combined with checking against breached password lists directly satisfies that guidance, blocking compromised credentials without imposing complexity or expiry requirements.

Why this answer

NIST SP 800-63B recommends a minimum password length of 8 characters (with 15+ encouraged for memorized secrets) and screening new passwords against lists of commonly used and breached passwords. This approach prioritizes length and blocklist checks over forced complexity and rotation.

Exam trap

The trap is that candidates default to legacy advice—complexity and 30-day rotation—when NIST has explicitly moved away from both in favor of length and breach-list screening.

How to eliminate wrong answers

Option A is wrong because allowing short passwords—even with complexity requirements—weakens resistance to brute-force and credential-stuffing attacks. Option B is wrong because NIST explicitly de-emphasizes composition rules (mixed case, symbols) in favor of length and blocklist screening. Option D is wrong because NIST advises against arbitrary periodic rotation, which drives users to predictable patterns like Password1! and Summer2024! rather than improving security.

8
MCQhard

A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?

A.Role-based access control (RBAC)
B.Mandatory access control (MAC)
C.Discretionary access control (DAC)
D.Attribute-based access control (ABAC)
AnswerB

MAC enforces access based on sensitivity labels assigned to objects and clearances held by subjects, with the system, not users, controlling label changes. The scenario's classification labels, clearances, and inability to bypass checks are defining traits of MAC, making this the correct model.

Why this answer

Mandatory access control bases decisions on labels attached to objects and clearances assigned to subjects, with enforcement handled by the system rather than by user discretion. The scenario's classification labels, clearance levels, and prohibition on bypassing checks all align with MAC. This model is typical in government and military settings where data sensitivity demands strict, non-discretionary control.

Exam trap

The trap here is assuming that any label-based or fine-grained scheme is attribute-based access control, when rigid label and clearance enforcement is specifically mandatory access control.

9
MCQmedium

In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?

A.Detective access control
B.Physical access control
C.Administrative access control
D.Logical access control
AnswerD

Logical access controls govern how subjects interact with systems and data, including session timeouts and authentication settings. A GPO enforcing a 15-minute inactivity lock restricts access through software configuration rather than physical barriers, directly satisfying the stem's requirement for automated session termination within Active Directory.

Why this answer

A GPO-enforced session lock is a logical access control because it is implemented in software/OS policy and governs how users interact with system resources after authentication. Logical controls include passwords, permissions, encryption, and session policies, all enforced by the operating system or applications rather than physical barriers or administrative procedures.

Exam trap

The trap here is confusing the policy document (administrative) with its technical enforcement (logical) — CC often tests whether candidates can distinguish administrative, logical/technical, and physical control categories.

How to eliminate wrong answers

Option A is wrong because detective controls identify and log events after they occur (e.g., IDS, audit logs), whereas a session lock actively enforces a restriction. Option B is wrong because physical controls protect tangible assets (locks, fences, guards), not OS-level session behavior. Option C is wrong because administrative controls are policies, procedures, and training — the GPO is the technical enforcement mechanism, not the policy document itself.

10
MCQmedium

A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?

A.Account lockout
B.Session timeout
C.Password complexity
D.Least privilege
AnswerA

Account lockout mitigates brute force by disabling an account after a set number of failed attempts, directly blocking continued password guessing from the single IP address. It satisfies the scenario's constraint of repeated authentication failures within a short period, though attackers could still target other accounts.

Why this answer

Account lockout is the most direct mitigation because it disables the account after a defined number of failed attempts, breaking the brute-force loop before the attacker can guess the password. It is a preventive control that directly targets the repeated-failure pattern described in the scenario.

Exam trap

CC often tests the distinction between preventive controls that stop the attack (lockout) and supporting controls that only make the attack harder (complexity) — candidates frequently pick password complexity because it 'sounds' like the right security answer.

How to eliminate wrong answers

Option B is wrong because session timeout only terminates idle sessions after successful authentication — it does nothing to stop repeated failed login attempts. Option C is wrong because password complexity increases the search space but does not stop an attacker from making unlimited guesses; it is a supporting control, not a mitigation for the observed attack. Option D is wrong because least privilege limits what an authenticated user can do, not how many times an attacker can attempt to authenticate.

11
Multi-Selecthard

An organization wants to implement defense in depth for its server room. Which THREE controls should be included?

Select 3 answers
A.Cable locks on all servers
B.Group Policy to enforce password complexity
C.Visitor sign-in log at the front desk
D.CCTV monitoring inside the server room
E.Biometric access control on the server room door
AnswersA, D, E

Physical tamper protection for the servers themselves, satisfying the defense-in-depth requirement for layered physical safeguards. Cable locks deter and delay removal or theft of server hardware, complementing perimeter, door and surveillance controls rather than duplicating them.

Why this answer

A is correct because cable locks are a physical (environmental) control that deters and prevents theft or removal of server hardware, directly supporting defense in depth at the server-room layer. D is correct because CCTV monitoring provides detective and deterrent physical security, recording activity inside the server room so incidents can be identified and investigated. E is correct because biometric access control on the server room door enforces strong, identity-based physical access control (something you are), restricting entry to authorized personnel.

B does not belong because Group Policy password complexity is a logical/technical control for user authentication, not a server-room physical control. C does not belong because a visitor sign-in log at the front desk is an administrative control for the building entrance, not a control protecting the server room itself.

Exam trap

CC often tests the distinction between physical, administrative, and technical controls — candidates pick GPO or visitor logs because they sound security-relevant, but the question scopes to the server room, so only physical controls qualify.

12
MCQeasy

Which access control principle restricts access to data based on the user's job role and tasks?

A.Separation of duties
B.Need to know
C.Defense in depth
D.Least privilege
AnswerB

Need to know restricts data access to what a user's role and tasks actually require, rather than granting broad access by seniority or department. This matches the stem's requirement to limit access based on job role and duties.

Why this answer

Need to know restricts access based on the specific data a user requires to perform their job tasks, which is exactly what the question describes. It is narrower than least privilege: least privilege limits the level of access (e.g., read vs. write), while need to know limits which specific data the user can see.

Exam trap

The trap is conflating least privilege with need to know — CC frequently presents scenarios where the user has the minimum permission level but still sees data they shouldn't, which is a need-to-know violation, not least privilege.

How to eliminate wrong answers

Option A is wrong because separation of duties splits critical tasks among multiple people to prevent fraud, not to restrict data based on job role. Option C is wrong because defense in depth is a layered-security strategy, not a data-access principle. Option D is wrong because least privilege grants the minimum permissions necessary for a role, but it does not by itself restrict which specific records or data categories a user can view — that is the need-to-know principle.

13
MCQeasy

A hospital's IT team issues each nurse a unique smart card that is inserted into a workstation before the nurse types a password. The nurse then accesses patient records permitted for the assigned ward. Which combination of access control concepts is being demonstrated?

A.Authentication by the smart card, authorization by the password, and identification by the permitted records.
B.Identification by the smart card, authorization by the password, and authentication by the permitted records.
C.Identification by the smart card, authentication by the password, and authorization by the permitted records.
D.Authorization by the smart card, identification by the password, and authentication by the permitted records.
AnswerC

The smart card supplies a claimed identity, which is the identification step. Typing a password verifies that claim, which is authentication. The patient records the nurse is allowed to view reflect authorization, the process of determining permitted resources after the identity has been proven. This scenario cleanly separates all three concepts and matches the standard CC access control model.

Why this answer

Identification is the act of claiming an identity, which the smart card performs by presenting a unique token. Authentication validates that claim, which the password accomplishes when it matches the stored credential. Authorization then determines which patient records the authenticated nurse may access.

Keeping these three steps distinct is fundamental to the access control concepts domain.

Exam trap

The trap here is treating the smart card as authentication when it is the token that presents the claimed identity before the password verifies it.

14
MCQmedium

An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:

A.Denial-of-service attacks
B.Brute-force attacks
C.Man-in-the-middle attacks
D.Phishing attacks
AnswerB

Locking an account after five failed attempts within fifteen minutes throttles repeated authentication guesses, directly disrupting automated brute-force attacks. The threshold and time window constrain the rate at which an attacker can try passwords, satisfying the stem's stated control design.

Why this answer

Account lockout after a small number of failed attempts within a short window is a classic brute-force mitigation: it throttles automated password-guessing by making repeated attempts impractical. Brute-force attacks rely on trying many passwords rapidly, so lockout thresholds and time windows directly disrupt that pattern. The control does not address DoS, MITM, or phishing, which operate through different mechanisms.

Exam trap

The trap here is confusing brute-force mitigation (lockout) with DoS prevention, when lockout can actually facilitate DoS rather than prevent it.

How to eliminate wrong answers

Option A is wrong because lockout policies can actually enable denial-of-service by letting attackers lock out legitimate users; they are not designed to prevent DoS. Option C is wrong because man-in-the-middle attacks intercept traffic between parties and are mitigated by encryption and certificate validation, not by login attempt limits. Option D is wrong because phishing tricks users into revealing credentials voluntarily; lockout does not prevent a user from handing over a valid password.

15
MCQhard

A defense contractor classifies documents as Confidential, Secret, or Top Secret and assigns each employee a clearance level. Access is permitted only when the employee's clearance meets or exceeds the document's classification, and users cannot change these labels. Which access control model is in use?

A.Discretionary access control (DAC)
B.Role-based access control (RBAC)
C.Rule-based access control
D.Mandatory access control (MAC)
AnswerD

MAC enforces access through system-assigned labels on objects and clearances on subjects, and users cannot modify those labels. The contractor's rule that clearance must meet or exceed the document classification is exactly the label-based comparison MAC performs. Because the labels are fixed by policy rather than owner choice, this scenario describes MAC.

Why this answer

Mandatory access control enforces access decisions using labels assigned to objects and clearances assigned to subjects, with the labels controlled by policy rather than by users. The requirement that a clearance meet or exceed a document's classification, combined with users being unable to change labels, is the defining behavior of MAC, making it the correct model for this defense contractor.

Exam trap

The trap here is treating any non-discretionary scheme as rule-based access control, when label-versus-clearance comparison that users cannot alter is specifically mandatory access control.

16
MCQmedium

A retail company issues managers a hardware token that generates a one-time code, which they enter after their password when signing in to the payroll system. A help desk technician asks why the company does not simply require longer passwords instead. Which statement best explains the security benefit of the token?

A.The token encrypts the password while it travels across the network, preventing interception.
B.The token replaces the need for authorization checks in the payroll system once the manager signs in.
C.The token ensures that the manager's password meets complexity requirements imposed by policy.
D.The token combines something the manager knows with something the manager has, so a stolen password alone is insufficient to sign in.
AnswerD

The password represents something the manager knows, while the hardware token represents something the manager has. Combining factors from two different categories is multi-factor authentication, and it means an attacker who only obtains the password still cannot produce the current one-time code. This directly explains the added protection that longer passwords alone cannot provide.

Why this answer

The hardware token supplies a second authentication factor from a different category than the password. A password is something the manager knows, and the token is something the manager has. Requiring both means a compromised password by itself is not enough to reach the payroll system, which is a stronger defense than increasing password length alone.

Exam trap

The trap here is treating any additional login step as simply stronger password policy, when the token's value comes from being a separate factor category rather than extra characters.

17
Multi-Selecthard

An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)

Select 3 answers
A.Sharing the root password among all administrators for convenience
B.Storing privileged passwords in an unencrypted text file
C.Applying the principle of least privilege to admin accounts
D.Using separate administrative accounts for daily tasks and privileged tasks
E.Implementing session recording and monitoring of privileged activities
AnswersC, D, E

Applying least privilege limits each admin account to only the permissions its role requires, shrinking the blast radius if credentials are compromised. For a PAM design, this directly satisfies the stem's constraint by removing standing excess rights, so privileged accounts cannot perform actions beyond their defined duties.

Why this answer

Option C is correct because applying the principle of least privilege ensures administrators receive only the minimum rights needed to perform their duties, reducing the attack surface and limiting damage from compromised accounts. Option D is correct because using separate administrative accounts for daily tasks and privileged tasks prevents day-to-day activities such as email and web browsing from exposing highly privileged credentials to malware or phishing. Option E is correct because implementing session recording and monitoring of privileged activities provides accountability, deters insider misuse, and creates an audit trail for forensic investigation of privileged actions.

Options A and B are not best practices: sharing the root password among all administrators destroys individual accountability and violates least privilege, while storing privileged passwords in an unencrypted text file exposes them to any user or process with file access and fails basic confidentiality controls.

Exam trap

CC often tests whether candidates can spot obvious PAM anti-patterns (shared root password, plaintext storage) versus genuine best practices (least privilege, separate accounts, session monitoring) — the distractors are deliberately extreme to test fundamentals.

18
MCQeasy

Which of the following is an example of a logical access control?

A.Security guard at entrance
B.Visitor logbook
C.Fence around building
D.Password complexity policy
AnswerD

Password complexity policies are logical controls because they govern how a subject authenticates to a system, rather than physically restricting entry. They satisfy the stem's requirement for a logical access control by enforcing rules on credentials within Microsoft Entra ID, unlike fences, locks or guards, which are physical controls.

Why this answer

A password complexity policy is a logical access control because it is enforced by software (the operating system or application) and governs how users authenticate. Logical controls include passwords, encryption, permissions, and session policies, all implemented in code rather than physical barriers or administrative procedures.

Exam trap

CC often tests whether candidates can classify controls into physical, logical/technical, and administrative categories — the trap is picking a physical item (guard, fence, logbook) when the question asks for a logical control.

How to eliminate wrong answers

Option A is wrong because a security guard is a physical control — a human presence that protects tangible assets. Option B is wrong because a visitor logbook is a physical/administrative control used to record entry, not a logical control. Option C is wrong because a fence is a physical barrier, clearly a physical control.

19
MCQeasy

In the identification and authentication process, which step occurs first?

A.Accounting
B.Identification
C.Authentication
D.Authorization
AnswerB

Identification precedes authentication because the system must first receive a claimed identity, such as a username or email address, before it can verify that claim. Authentication then validates the credential against that identity. This ordering satisfies the stem's requirement that identification occurs first in the process.

Why this answer

Identification is the first step because the user must claim an identity (e.g., username) before the system can authenticate it. Authentication verifies that claim, authorization determines what the user can do, and accounting logs the activity — all of which depend on identification occurring first.

Exam trap

CC often tests the order of the IAAA model — candidates sometimes pick authentication first because it 'feels' like the security step, but identification must always precede it.

How to eliminate wrong answers

Option A is wrong because accounting (audit logging) occurs after authentication and authorization, recording what the user did. Option C is wrong because authentication verifies the identity claim, but it cannot happen until the user has first presented an identity. Option D is wrong because authorization grants permissions after authentication succeeds, so it cannot be first.

20
MCQmedium

A hospital's IT security team reviews how nurses access patient records. They find that a nurse who works in the cardiology unit can also open records for the oncology unit, even though the nurse never treats those patients. The team wants access decisions to be based on the department a nurse is assigned to plus the specific treatment relationship. Which access control model should they implement?

A.Discretionary access control (DAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Attribute-based access control (ABAC)
AnswerD

ABAC evaluates attributes of the subject, resource, action, and environment, so a policy can allow access only when the nurse's department attribute matches the record's department and a treatment relationship exists. This precisely fits the hospital's requirement to combine department assignment with the specific clinician-patient relationship, producing dynamic decisions that static roles cannot express.

Why this answer

Attribute-based access control evaluates multiple characteristics at decision time, allowing the hospital to combine the nurse's department attribute with the treatment relationship between clinician and patient. That dynamic evaluation restricts cardiology nurses to records they are genuinely involved with, which neither static roles nor owner-discretion models can express without excessive role proliferation or inconsistent enforcement.

Exam trap

The trap here is assuming that role-based access control can express any condition, when it cannot easily encode dynamic relationships such as a specific clinician treating a specific patient.

21
MCQeasy

What is the process of claiming an identity called?

A.Authentication
B.Authorization
C.Accountability
D.Identification
AnswerD

Identification is the act of a subject presenting a claimed identity, such as a username, before any proof is offered. Authentication then verifies that claim, and authorisation grants access. The question asks specifically about claiming, so identification is the process named.

Why this answer

Identification is the process of claiming an identity — a subject asserts who they are (e.g., by presenting a username, smart card, or biometric sample) before any verification occurs. Authentication then validates that claim, and authorization determines what the verified identity may do. In the ISC2 access control model, identification is the first step in the AAA/identity lifecycle.

Exam trap

The trap here is conflating identification with authentication — candidates often pick 'Authentication' because both involve presenting credentials, but identification is merely the claim, while authentication is the verification of that claim.

How to eliminate wrong answers

Option A is wrong because authentication is the act of verifying a claimed identity (e.g., checking a password or certificate), not the act of claiming it. Option B is wrong because authorization is the process of granting or denying access rights to a verified identity, which occurs after authentication. Option C is wrong because accountability is the ability to trace actions back to a specific identity via logs and audit trails, not the act of asserting identity.

22
Multi-Selectmedium

A security team is reviewing how access control is enforced across a corporate environment. Which two statements accurately describe the relationship between identification, authentication, and authorization? (Choose two.)

Select 2 answers
A.Authorization decisions are made after authentication succeeds, based on the verified identity's permissions.
B.Identification asserts an identity, while authentication verifies that the asserted identity is genuine.
C.Identification alone is sufficient to grant access to protected resources in a secure system.
D.A user can be authorized for a resource without ever being authenticated to the system.
E.Authentication and authorization are the same process because both determine whether a user may access a resource.
AnswersA, B

Authorization determines what a verified identity may do, and it depends on knowing who the user is, which requires successful authentication first. Granting permissions before verifying identity would allow impersonation. This statement correctly reflects that authorization follows authentication and relies on the resulting identity context.

Why this answer

Identification claims an identity, authentication verifies that claim, and authorization grants permissions based on the verified identity. The two correct statements capture these distinct roles and their proper sequence. The remaining statements incorrectly merge authentication with authorization, allow authorization without authentication, or treat identification as sufficient for access.

Exam trap

The trap here is treating authentication and authorization as interchangeable, when one verifies identity and the other determines permitted actions.

23
MCQeasy

A small design studio stores client files on a shared server. Each project folder is owned by the designer who created it, and that designer decides which colleagues may open the folder by granting permissions directly to individual accounts. Which access control model is the studio using?

A.Role-based access control
B.Discretionary access control
C.Rule-based access control
D.Mandatory access control
AnswerB

Discretionary access control places the decision with the resource owner, who may grant or revoke access at their discretion. Because each designer owns the project folder and personally decides which colleagues can open it by assigning permissions to individual accounts, the model matches discretionary access control exactly. The owner's judgment, not a central policy, determines who gets in.

Why this answer

Discretionary access control is defined by owner discretion: the person who owns a resource decides who else may use it. Each designer owns their project folder and personally grants permissions to individual colleagues, so the access decision rests with the owner rather than with central labels, roles, or global rules.

Exam trap

The trap here is assuming that permissions granted to individual accounts automatically mean role-based access control, when the deciding factor is who holds the authority to grant them.

24
MCQmedium

A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?

A.Separation of duties
B.Need-to-know
C.Least privilege
D.Defense in depth
AnswerC

Least privilege means granting only the access needed for a task, so routine email and browsing run without administrative rights. Separating the privileged account limits exposure: compromise of the daily-use account cannot yield administrative control over the system.

Why this answer

Using a separate non-privileged account for daily tasks like email and web browsing while reserving the admin account for administrative work is a direct application of least privilege. Least privilege means users should have only the minimum access necessary for their current task, and separating admin from daily use reduces the attack surface of privileged credentials. This practice limits exposure of administrative rights to routine activities that could be compromised.

Exam trap

The trap is conflating least privilege with separation of duties; both involve splitting access, but least privilege is about minimizing rights for a task, while separation of duties is about distributing critical functions across people.

How to eliminate wrong answers

Option A is wrong because separation of duties divides critical functions among different people to prevent fraud, not the practice of using separate accounts for admin versus daily tasks by the same person. Option B is wrong because need-to-know governs access to information based on job requirements, not the separation of privileged and non-privileged accounts. Option D is wrong because defense in depth is a layered security strategy, not the specific principle of minimizing privileges for daily activities.

25
MCQeasy

Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?

A.Least privilege
B.Need-to-know
C.Defense in depth
D.Separation of duties
AnswerA

Least privilege grants users only the minimum permissions required for their job functions, directly satisfying the stem's constraint. Unlike role-based access control, which assigns permissions by role, least privilege limits each user's access to precisely what their tasks demand, reducing the attack surface and preventing unnecessary privilege accumulation.

Why this answer

The principle of least privilege dictates that users are granted only the minimum permissions necessary to perform their job functions. This reduces the attack surface and limits potential damage from accidental or malicious actions.

Exam trap

The trap is confusing least privilege with need-to-know, which is a subset of least privilege focused on information access rather than all permissions.

How to eliminate wrong answers

Option B is wrong because need-to-know is about restricting access to information based on necessity, but it is more specific to data confidentiality and does not encompass all permissions. Option C is wrong because defense in depth is a layered security strategy, not a principle for granting permissions. Option D is wrong because separation of duties involves dividing tasks among multiple people to prevent fraud, not about minimizing permissions.

26
MCQmedium

A retail company issues contract workers temporary accounts that automatically expire after 30 days, and it reviews all active accounts each quarter to remove those no longer needed. Which access control administration practice does the quarterly review represent?

A.User provisioning
B.Separation of duties
C.Access review or recertification
D.Least privilege
AnswerC

An access review, also called recertification, periodically examines existing accounts and entitlements to confirm they are still required and to revoke those that are not. Reviewing all active accounts each quarter to remove unneeded ones is precisely this practice. It complements the automatic expiration of temporary accounts by catching access that outlives its business need.

Why this answer

Periodically reviewing active accounts to confirm each is still needed and removing those that are not is an access review, also known as recertification. It works alongside automated expiration of temporary accounts by catching entitlements that persist beyond their business justification, helping the company keep access aligned with current needs and supporting least privilege over time.

Exam trap

The trap here is naming the goal rather than the activity, so candidates pick least privilege when the scenario describes the recurring review process itself.

27
MCQhard

An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?

A.COBIT
B.ISO 27001
C.NIST SP 800-63
D.PCI DSS
AnswerC

NIST SP 800-63 mandates an eight-character minimum and screens new passwords against breach corpora, directly satisfying both the length floor and the ban on compromised credentials. Its guidance also favours length over forced complexity and rotation, matching the policy's emphasis on breached-password blocking rather than composition rules.

Why this answer

NIST SP 800-63 (Digital Identity Guidelines) explicitly addresses authenticator and memorized-secret requirements, including minimum length and screening against breached-password lists (e.g., in SP 800-63B, section 5.1.1.2). The described policy — 8-character minimum plus blocklist of common/breached passwords — mirrors NIST's guidance almost verbatim.

Exam trap

The trap here is confusing governance/management frameworks (COBIT, ISO 27001) with technical identity guidelines — candidates often pick ISO 27001 because it 'sounds like security policy,' missing that only NIST SP 800-63B prescribes the specific password rules described.

How to eliminate wrong answers

Option A is wrong because COBIT is an IT governance and control framework focused on aligning IT with business objectives, not on specific password composition rules. Option B is wrong because ISO 27001 is an information security management system standard that mandates a policy framework but does not prescribe exact password length or breach-list screening. Option D is wrong because PCI DSS focuses on protecting cardholder data and specifies requirements like password complexity and length (Req 8), but does not specifically mandate screening against breach databases the way NIST SP 800-63B does.

28
MCQeasy

A small marketing firm wants to give each employee a single set of credentials that works for the corporate email system, the cloud CRM, and the internal file share. The IT manager proposes using a central identity store so users do not have to remember separate passwords. Which concept is the IT manager describing?

A.Multifactor authentication (MFA)
B.Single sign-on (SSO)
C.Federated identity management
D.Role-based access control (RBAC)
AnswerB

SSO lets a user authenticate once to a central identity provider and then access multiple independent applications without re-entering credentials for each one. In this scenario, the marketing firm wants one credential set to reach email, CRM, and file services, which is exactly the problem SSO solves through token or assertion exchange between the identity provider and each relying application.

Why this answer

The firm's goal is one credential set that unlocks several independent applications, which is the defining purpose of single sign-on. SSO relies on a central identity provider that authenticates the user once and then issues assertions or tokens to each connected application, removing repeated password prompts while still allowing each application to make its own authorization decisions.

Exam trap

The trap here is confusing a login-convenience technology with an authorization model, so candidates pick role-based access control when the scenario is really about reducing the number of authentication events.

29
Multi-Selecthard

An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)

Select 3 answers
A.Background checks for all visitors
B.Issuance of temporary visitor badges
C.Visitor sign-in with host notification
D.Escort policy requiring visitors to be accompanied
E.Biometric authentication for visitors
AnswersB, C, D

Temporary visitor badges give each visitor a visible, time-bound credential that distinguishes them from staff and supports accountability. This satisfies the visitor management policy's need to identify and track non-employees on site, complementing sign-in and escort controls.

Why this answer

Option B (issuance of temporary visitor badges) is correct because a visitor management policy must provide a means of visually identifying non-employees, and temporary badges with expiration dates or distinct colors let staff distinguish visitors from employees and enforce access limits. Option C (visitor sign-in with host notification) is correct because logging each visitor's identity, time of entry, and purpose, then alerting the internal host, creates an audit trail and ensures visitors are expected and accounted for. Option D (escort policy requiring visitors to be accompanied) is correct because requiring visitors to remain with an authorized employee prevents unescorted access to sensitive areas and is a standard physical security control.

Option A is not appropriate because background checks for all visitors are disproportionate and operationally impractical for routine guests such as delivery personnel or interview candidates. Option E is not appropriate because biometric authentication for visitors is costly, raises privacy and consent concerns, and is unnecessary when badges, sign-in, and escorts already provide adequate control.

Exam trap

The trap is over-engineering the policy — candidates select background checks or biometrics because they sound 'more secure,' but the exam expects proportionate, standard visitor controls: badges, sign-in, and escorts.

30
MCQhard

An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?

A.Organization Unit
B.Object Unit
C.Operating Unit
D.Organizational Unit
AnswerD

In LDAP distinguished names, OU stands for Organizational Unit — a container object used to group directory entries, typically by department or function. Here OU=Sales places John Smith within the Sales organisational unit beneath the company's domain components.

Why this answer

Option D is correct because in LDAP distinguished names, OU stands for 'Organizational Unit'. An OU is a container object within a directory that is used to organize entries such as users, groups, and computers. In the DN 'CN=John Smith,OU=Sales,DC=company,DC=com', the OU=Sales indicates that John Smith resides in the Sales organizational unit within the company.com domain.

Exam trap

The trap here is the subtle wording difference between 'Organizational Unit' (correct) and 'Organization Unit' (incorrect) — candidates who know the concept but not the exact term may pick the wrong option.

How to eliminate wrong answers

Option A is wrong because 'Organization Unit' is not a standard LDAP term; the correct term is 'Organizational Unit'. Option B is wrong because 'Object Unit' is not an LDAP concept — objects are individual entries, not units. Option C is wrong because 'Operating Unit' is a business term, not an LDAP directory component.

31
Multi-Selectmedium

A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)

Select 2 answers
A.Place a sign on the door stating that the area is restricted to authorized personnel only.
B.Disable the door alarm and logging functions to speed up employee entry during peak hours.
C.Require employees to display a visible badge at all times while inside the facility.
D.Install a mantrap that admits one authenticated person at a time between two interlocking doors.
E.Publish the entrance door code on the company intranet so employees can memorize it.
AnswersC, D

Visible badges let staff and security personnel quickly distinguish authorized individuals from visitors or intruders, which reinforces the effectiveness of the entrance control. Badge display supports accountability and makes unauthorized presence easier to challenge. It is a widely accepted physical control that complements authentication at the door without impeding normal employee movement.

Why this answer

Effective physical access control combines preventive enforcement with accountability. A mantrap ensures each entrant authenticates individually, eliminating tailgating, while mandatory visible badges let anyone on site verify that a person is authorized. Together they admit legitimate employees efficiently while making unauthorized entry difficult to conceal, which is exactly what a well-designed entrance control should achieve.

Exam trap

The trap here is accepting signage or convenience shortcuts as equivalent to actual access enforcement mechanisms.

32
MCQeasy

Which of the following is a recommended practice for administrative accounts?

A.Use the same account for daily work and admin tasks
B.Grant admin rights to all users for convenience
C.Use a separate admin account distinct from daily use account
D.Disable all admin accounts to improve security
AnswerC

Separating administrative credentials from daily-use accounts enforces least privilege and limits blast radius: routine browsing, email and phishing exposure cannot compromise privileged access. This directly satisfies the recommended practise of isolating elevated permissions from everyday activity.

Why this answer

Using a separate administrative account distinct from a daily-use account enforces least privilege and separation of duties. If the daily account is compromised via phishing or malware, the attacker does not automatically gain administrative rights. This practice also ensures accountability, as administrative actions are logged under a dedicated identity.

Exam trap

The trap here is the misconception that convenience (using one account) or extreme measures (disabling all admin accounts) are acceptable; the exam expects recognition that separation of duties and least privilege are key.

How to eliminate wrong answers

Option A is wrong because using the same account for daily work and admin tasks violates least privilege and increases the blast radius of a compromise. Option B is wrong because granting admin rights to all users for convenience is a direct violation of least privilege and dramatically increases risk. Option D is wrong because disabling all admin accounts would prevent legitimate administrative tasks and is not a recommended practice; instead, admin accounts should be secured and monitored.

33
MCQmedium

According to NIST SP 800-63, which password policy is recommended to enhance security?

A.Allow passwords as short as 4 characters
B.Enforce maximum complexity with special characters and numbers
C.Require frequent password changes every 30 days
D.Favor length over complexity and check against breached password lists
AnswerD

NIST SP 800-63 favours password length over composition rules, since complexity encourages predictable patterns and reuse. Breached-list screening blocks credentials already exposed in leaks, directly satisfying the guidance's requirement to reject compromised secrets rather than merely enforcing character classes.

Why this answer

NIST SP 800-63B recommends favoring password length over complexity and screening new passwords against lists of commonly used and breached passwords. Length increases entropy far more effectively than forcing special characters, and breach-list checks block credentials attackers already possess. The same guidance also discourages forced periodic rotation absent evidence of compromise.

Exam trap

The trap is the legacy mindset that 'more complexity and frequent rotation equals more secure' — candidates raised on old policy templates pick complexity or 30-day rotation, missing NIST's modern length-and-breach-check stance.

How to eliminate wrong answers

Option A is wrong because allowing 4-character passwords is far below NIST's recommended minimum of 8 characters (with 15 recommended for memorized secrets in some contexts) and drastically reduces the search space. Option B is wrong because NIST explicitly moved away from mandatory composition rules (mixed case, digits, symbols), which push users toward predictable patterns like 'Password1!' and increase help-desk burden. Option C is wrong because NIST no longer recommends arbitrary periodic expiration (e.g., every 30 days); frequent changes degrade password quality and are only warranted when compromise is suspected.

34
MCQeasy

A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerD

Separation of duties splits a critical task across multiple identities so no single person controls it end to end. Requiring two distinct managers to approve each financial transaction enforces this by preventing one individual from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.

Why this answer

Separation of duties (SoD) requires that critical tasks be divided among multiple people so that no single individual can complete a sensitive transaction alone. Requiring two managers to approve financial transactions is the textbook example: it prevents fraud and errors by ensuring collusion is needed to bypass the control. SoD is a foundational principle in ISC2's access control domain.

Exam trap

The trap is confusing separation of duties with least privilege — both limit what a user can do, but SoD specifically requires multiple people to complete a task, while least privilege limits the scope of a single user's access.

How to eliminate wrong answers

Option A is wrong because need-to-know restricts access to information based on job requirements, not on splitting approval authority across people. Option B is wrong because defense in depth is the layering of multiple controls (physical, technical, administrative) so that no single failure compromises security — it is a strategy, not a specific approval rule. Option C is wrong because least privilege grants users only the minimum access needed to perform their jobs; it limits permissions but does not require two-person approval.

35
MCQmedium

A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?

A.Discretionary access control (DAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Rule-based access control
AnswerB

RBAC grants permissions to roles, and users receive rights by being assigned to a role. When the employee moves from the Teller role to the Loan Officer role, the old role's permissions drop away and the new role's permissions apply, exactly as described. This role-to-permission mapping with automatic reassignment is the defining behavior of role-based access control.

Why this answer

Assigning rights to roles and then placing users into those roles is the essence of role-based access control. The transfer scenario shows the key benefit: permissions follow the job function, so moving an employee between departments automatically strips old rights and applies new ones without editing each user's individual access list.

Exam trap

The trap here is treating any centrally managed permission scheme as mandatory access control when the scenario actually describes role assignment without security labels.

36
Multi-Selecthard

An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)

Select 3 answers
A.Fencing and bollards around the property
B.Biometric reader on server room door
C.Encryption of data at rest
D.Intrusion detection system on the network
E.Access badge system at building entrance
AnswersA, B, E

Fencing and bollards form the outermost deterrent layer, delaying or preventing physical approach to the facility. They satisfy defence in depth by forcing attackers through successive boundaries before reaching internal controls such as locks or biometrics.

Why this answer

Option A (fencing and bollards around the property) is correct because these are perimeter physical controls that create the outermost defensive layer, deterring or blocking vehicles and intruders before they reach the building. Option B (biometric reader on server room door) is correct because it is an interior physical access control that authenticates a person's unique biological trait, adding a stronger layer protecting the high-value server room beyond the building entrance. Option E (access badge system at building entrance) is correct because it is a physical access control at the facility boundary, verifying authorized personnel and forming a layer between the perimeter and the server room.

Option C (encryption of data at rest) is not a physical control but a logical/cryptographic control protecting data confidentiality. Option D (intrusion detection system on the network) is a logical/technical monitoring control, not a physical security layer.

Exam trap

The trap is mixing logical and physical controls — candidates see 'encryption' and 'IDS' as security measures and include them, forgetting the question specifically asks for layered PHYSICAL controls.

37
Multi-Selecthard

A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)

Select 2 answers
A.Granting one senior manager both the ability to create vendors and the ability to approve payments to those vendors
B.Allowing any employee with payment approval rights to also modify the approval limits assigned to their own account
C.Assigning all payment-related duties to a single trusted administrator to simplify the process
D.Applying a system constraint that prevents the same user account from both entering and approving a payment
E.Requiring one employee to initiate a payment and a different employee to approve it
AnswersD, E

A technical constraint that blocks one account from performing both steps enforces separation of duties automatically rather than relying on policy alone. It removes the possibility of a single user completing the whole transaction, which is exactly what the firm needs. This makes the control reliable and auditable in the payment system.

Why this answer

Separation of duties ensures no single person can complete a sensitive transaction end to end. Requiring different employees to initiate and approve payments, and enforcing that split with a system constraint that blocks one account from doing both, both create an independent check. The other practices concentrate or allow circumvention of those duties, which undermines the control.

Exam trap

The trap here is equating trust in a specific person with an effective control, which leads candidates to accept consolidating payment duties as a reasonable simplification.

38
MCQeasy

A payroll clerk can view and edit employee salary records but cannot approve her own expense reimbursements, even though she processes reimbursements for other staff. Which access control principle does the restriction on approving her own reimbursements best illustrate?

A.Least privilege
B.Mandatory access control
C.Need to know
D.Separation of duties
AnswerD

Separation of duties splits a sensitive transaction across more than one person so no single individual controls the entire process. Because the clerk processes reimbursements, letting her also approve her own claim would give her unchecked control over a payment to herself. Requiring a different approver for her own reimbursement prevents that conflict and is the textbook application of separation of duties.

Why this answer

Separation of duties ensures that a single person cannot complete a sensitive transaction alone, reducing the risk of fraud or undetected error. Since the clerk can process reimbursements but is barred from approving her own, the organization has split control of the payment process across multiple people, which is exactly what separation of duties accomplishes.

Exam trap

The trap here is choosing least privilege simply because a restriction exists, when the real reason is preventing one person from controlling both sides of a sensitive transaction.

39
Multi-Selectmedium

A security team is designing a physical access control system for a data center. They want to implement controls that verify a person's identity based on unique biological characteristics. Which two of the following are examples of biometric access controls? (Choose two.)

Select 2 answers
A.Smart card reader
B.Proximity badge
C.Personal identification number (PIN) pad
D.Retina scanner
E.Fingerprint scanner
AnswersD, E

A retina scanner analyzes the unique pattern of blood vessels in the eye, which is a biological characteristic. This makes it a biometric control that verifies identity based on inherence. It is well suited for high-security environments like data centers because the trait is difficult to replicate, and it directly matches the requirement for biological verification.

Why this answer

Biometric access controls verify identity using unique biological traits. Retina scanners and fingerprint scanners both measure inherent physical characteristics, making them valid biometric controls for the data center. Smart cards, PIN pads, and proximity badges rely on possession or knowledge factors instead, so they do not satisfy the requirement for biological verification even though they may be used alongside biometrics in a layered design.

Exam trap

The trap here is assuming that any electronic access device, such as a smart card or badge reader, counts as biometric because it is used for access control.

40
Multi-Selecthard

A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)

Select 2 answers
A.Implementing data classification labels
B.Using a single sign-on solution
C.Requiring two-factor authentication
D.Granting all employees access to the company directory
E.Providing access to customer data only for customer support staff
AnswersA, E

Data classification labels tag information by sensitivity, enabling need-to-know enforcement because access decisions can be tied to clearance and label matching. Without labels, administrators cannot determine who legitimately requires specific data, so this practice directly supports least-privilege need-to-know access.

Why this answer

Option A is correct because implementing data classification labels (e.g., Public, Internal, Confidential, Restricted) tags information with its sensitivity level, which is the foundation for need-to-know decisions—users are only granted access to data whose classification matches their role and clearance. Option E is correct because restricting customer data access to only customer support staff is a direct application of need-to-know: access is limited to those whose job function requires that data, excluding other employees. Option B (single sign-on) is an authentication convenience that centralizes login but does not by itself limit access to only what a user needs.

Option C (two-factor authentication) strengthens identity verification but addresses authentication assurance, not authorization scope. Option D (granting all employees access to the company directory) violates need-to-know by giving broad access regardless of job requirement.

Exam trap

The trap here is confusing authentication controls (SSO, 2FA) with authorization controls — candidates pick B or C because they sound like security best practices, but need-to-know is strictly about limiting data access based on job function.

41
MCQhard

An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?

A.OU = Organizational Unit; DC = Domain Component
B.OU = Organizational Unit; DC = Domain Controller
C.OU = Organizational Unit; DC = Distinguished Component
D.OU = Object Unit; DC = Domain Component
AnswerA

In LDAP distinguished names, OU identifies the Organizational Unit container holding the object, while DC marks each Domain Component of the DNS-based directory namespace. Reading right to left, DC=com and DC=company define the domain hierarchy, and OU=Sales places John Smith within the Sales organisational unit.

Why this answer

In LDAP distinguished names, OU stands for Organizational Unit and DC stands for Domain Component. These are the standard RDN attribute types defined in RFC 4519 and used to build hierarchical directory paths, so option A is the correct expansion.

Exam trap

The trap is the DC acronym collision — candidates who work with Active Directory reflexively read DC as Domain Controller instead of Domain Component.

How to eliminate wrong answers

Option B is wrong because DC does not mean Domain Controller in LDAP DN syntax — Domain Controller is an Active Directory server role, not a DN attribute, and conflating the two is a classic naming trap. Option C is wrong because DC is not 'Distinguished Component'; the term 'distinguished' refers to the DN as a whole, not to the DC attribute. Option D is wrong because OU is not 'Object Unit' — the correct expansion is Organizational Unit, and misnaming it signals a misunderstanding of the X.500 directory model.

42
Multi-Selecthard

A financial services firm is deploying a new customer portal. Auditors have required that access decisions consider the user's department, the data classification of the record, the time of day, and whether the request originates from a managed corporate device. The security architect proposes Attribute-Based Access Control (ABAC). Which two statements correctly describe how ABAC satisfies these requirements? (Choose two.)

Select 2 answers
A.ABAC decisions are made by comparing the user's security clearance against the classification label of the object, with no other inputs considered.
B.ABAC policies can be expressed so that access is granted only when the department matches the record's owning business unit, the classification is permitted for that department, the request occurs during approved hours, and the device is managed.
C.ABAC removes the need for authentication because attribute values alone are sufficient to prove a user's identity.
D.ABAC evaluates policies built from attributes of the subject, the object, the action, and the environment, allowing the firm to combine department, classification, time, and device posture in a single decision.
E.ABAC requires that each user be assigned exactly one static role, and all access is then determined solely by that role membership.
AnswersB, D

ABAC supports compound policy conditions that must all evaluate true before access is granted. Expressing the department match, classification allowance, approved hours, and managed-device requirement as a combined policy directly implements the auditors' four conditions. This is a correct description of how attribute-driven rules translate business requirements into enforceable access decisions.

Why this answer

ABAC makes decisions by evaluating policies over attributes of the subject, object, action, and environment, which allows department, data classification, time, and device posture to be combined into a single enforceable rule. The two correct statements capture that multi-attribute evaluation and the ability to express compound conditions that must all hold before access is granted.

Exam trap

The trap here is confusing ABAC with role-based or label-based models, since role membership and clearance labels can be attributes, but neither alone can express the time and device conditions required.

43
MCQhard

A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?

A.Least privilege
B.Separation of duties
C.Need-to-know
D.Defense in depth
AnswerA

Granting full financial database access to a user who only views quarterly reports exceeds their job requirements. Least privilege requires granting only the minimum access needed for assigned duties, so this excessive entitlement violates that principle most directly.

Why this answer

Least privilege requires granting only the minimum permissions necessary to perform job functions.

44
MCQhard

A Privileged Access Management (PAM) solution is used to:

A.Control and monitor privileged accounts and sessions
B.Encrypt data at rest
C.Manage user passwords and enforce complexity
D.Provide single sign-on for all applications
AnswerA

PAM brokers access to privileged credentials, vaulting them and injecting sessions through a controlled jump host. This delivers both control (least privilege, approval workflows, credential rotation) and monitoring (keystroke and command logging), satisfying the requirement to govern administrative accounts rather than ordinary user identities.

Why this answer

PAM solutions control, monitor, and audit privileged access to critical systems.

45
MCQhard

An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerB

Layering fencing, badge readers, biometrics and cable locks creates successive independent barriers, so defeating one control still leaves others. This matches defence in depth, which the stem's layered approach exemplifies, rather than single-mechanism concepts such as least privilege or separation of duties.

Why this answer

Defense in depth is the practice of layering multiple independent security controls so that if one fails, others continue to protect the asset. The scenario describes physical controls at progressively deeper levels — perimeter fencing, badge readers at entrances, biometric scanners in server rooms, and cable locks on laptops — each adding a distinct barrier. This layered approach is the textbook definition of defense in depth.

Exam trap

The trap here is confusing defense in depth with least privilege or need-to-know, since all three involve restricting access — but only defense in depth describes layering multiple independent controls.

How to eliminate wrong answers

Option A is wrong because need-to-know is an information access principle that restricts data to individuals whose job requires it, and it does not describe physical barriers like fences or cable locks. Option C is wrong because least privilege refers to granting users only the minimum permissions necessary to perform their job functions, which is an authorization concept rather than a layered physical security strategy. Option D is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error, which is unrelated to the physical security layers described.

46
MCQmedium

An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?

A.Separation of duties
B.Defense in depth
C.Need to know
D.Least privilege
AnswerA

Separation of duties splits a sensitive transaction across two distinct approvers, so no single manager can authorise a payment alone. Requiring two different managers for transactions above $10,000 directly enforces this principle by preventing unilateral action and creating mutual oversight.

Why this answer

Separation of duties ensures that no single individual has complete control over a critical action, reducing the risk of fraud or error.

47
MCQeasy

A hospital's data center uses a mantrap at its main entrance. A nurse badges in at the outer door, steps into a small glass vestibule, and the outer door locks before the inner door unlocks. What security goal does this design primarily achieve?

A.Establishing identification of the nurse to the access control system
B.Preventing tailgating by allowing only one person to pass at a time
C.Providing non-repudiation of the nurse's badge transaction
D.Enforcing least privilege for staff entering the data center
AnswerB

A mantrap uses interlocked doors so the second door cannot open until the first is secured, and typically only one person fits in the vestibule. This physically separates individuals, defeating the common practice of an unauthorized person following an authorized badge holder through a single door. That is precisely the anti-tailgating function the scenario describes.

Why this answer

The interlocked-door vestibule is a classic anti-tailgating control: it forces a one-person-at-a-time transition between security zones so an unauthorized individual cannot slip in behind an authorized badge holder. The nurse's badge handles identification and authentication; the mantrap's distinct contribution is preventing piggybacking through the doorway.

Exam trap

The trap here is assuming any physical entry control automatically enforces least privilege rather than recognizing the mantrap's specific role in stopping tailgating.

48
Multi-Selecteasy

Which TWO are examples of logical access controls? (Select TWO.)

Select 2 answers
A.Fencing around the property
B.Password complexity requirements
C.Guard at building entrance
D.Biometric door lock
E.Account lockout policy
AnswersB, E

Password complexity requirements are a logical access control because they govern authentication through software-enforced rules on the credential itself, restricting who can gain system access. No physical barrier is involved, satisfying the question's requirement for a logical, rather than physical, control.

Why this answer

Password complexity requirements (B) are a logical access control because they are enforced in software by the operating system or directory service (e.g., via Group Policy password policy or /etc/security/pwquality.conf) to govern how a user authenticates, not to physically restrict movement. Account lockout policy (E) is likewise logical: it is a software-enforced setting that disables an account after a defined number of failed logon attempts within a set window, mitigating brute-force attacks against the authentication process. Both operate on the logical layer of identity and authentication rather than on physical barriers.

By contrast, fencing around the property (A), a guard at the building entrance (C), and a biometric door lock (D) are physical access controls, since they restrict who can physically enter a location or structure.

Exam trap

CC often tests the confusion between physical and logical controls by including biometrics, which can be either depending on context — the trap is assuming biometrics is always logical when the scenario describes a door lock.

49
MCQmedium

A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?

A.Separation of duties
B.Defense in depth
C.Need-to-know
D.Least privilege
AnswerD

Default-deny firewall rules permit only explicitly required services, embodying least privilege by granting the minimum access necessary. This satisfies the stem's constraint of blocking all inbound traffic except specific necessary services, rather than relying on implicit trust.

Why this answer

Blocking all inbound traffic except explicitly required services is the definition of least privilege applied to network access control — granting only the minimum access necessary for business function. The firewall default-deny with specific allow rules embodies this principle by minimizing the attack surface.

Exam trap

CC often tests the confusion between least privilege (minimum necessary access) and defense in depth (layered controls) — candidates pick 'defense in depth' whenever a firewall is mentioned, even when the scenario is about minimizing allowed access.

How to eliminate wrong answers

Option A is wrong because separation of duties is an administrative control that divides critical tasks among different people to prevent fraud or error, not a network traffic filtering concept. Option B is wrong because defense in depth means layering multiple independent controls (firewall, IDS, endpoint, MFA); the scenario describes a single filtering philosophy, not layered defenses. Option C is wrong because need-to-know governs access to information based on job relevance, typically for data classification, not which network services are permitted through a firewall.

50
MCQmedium

An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?

A.Phishing
B.Brute-force attack
C.Social engineering
D.Man-in-the-middle attack
AnswerB

Lockout thresholds directly throttle repeated authentication failures, so an attacker cannot iterate passwords indefinitely. The 5-attempts-in-15-minutes constraint caps the guessing rate, defeating brute-force attempts while allowing legitimate users to retry after the lockout window expires.

Why this answer

Account lockout after 5 failed attempts within 15 minutes is a classic defense against brute-force attacks, which rely on rapidly submitting many password guesses until one succeeds. By locking the account after a small number of failures, the control drastically reduces the number of attempts an attacker can make in a given time window, making automated guessing impractical. This is a standard mitigation recommended by frameworks like NIST and CIS.

Exam trap

The trap here is confusing brute-force with other credential-related attacks; candidates may pick phishing because both involve passwords, but only brute-force is mitigated by limiting failed attempts.

How to eliminate wrong answers

Option A is wrong because phishing is a social-engineering technique that tricks users into revealing credentials voluntarily; account lockout does not prevent a user from handing over a password. Option C is wrong because social engineering targets human trust and manipulation, not automated authentication attempts, so lockout thresholds have no effect. Option D is wrong because a man-in-the-middle attack intercepts or alters traffic between two parties; account lockout does not address session hijacking or credential interception.

51
MCQmedium

In the context of identification and authentication, which of the following is an example of authentication?

A.Entering a username
B.Being assigned a user ID
C.Providing a fingerprint scan
D.Swiping an access badge
AnswerC

A fingerprint scan supplies a biometric credential that the system matches against a stored template, verifying the claimed identity. Authentication confirms who you are, whereas identification merely claims an identity. The scan therefore satisfies the stem's requirement for an authentication example, unlike identifiers such as a username, which only assert identity.

Why this answer

Authentication is the process of verifying a claimed identity, typically through something the user knows, has, or is. Providing a fingerprint scan is an example of authentication because it uses a biometric factor to verify the user's identity. The other options are related to identification, not authentication.

Exam trap

CC often tests the difference between identification and authentication, and candidates frequently confuse the two, selecting options that are actually identification (like entering a username) as authentication.

How to eliminate wrong answers

Option A is wrong because entering a username is an example of identification, where the user claims an identity, not authentication. Option B is wrong because being assigned a user ID is also part of identification, establishing a unique identifier for the user. Option D is wrong because swiping an access badge can be either identification or authentication depending on context; however, in typical security models, a badge alone often serves as identification (something you have) but may not verify identity without a PIN or biometric, so it is not the best example of authentication compared to a fingerprint scan.

52
MCQmedium

A financial services firm classifies documents as Public, Internal, Confidential, and Restricted. Access to Restricted documents is determined solely by the document's classification label and the user's clearance level, and users cannot change either value. Which statement best describes this arrangement?

A.It is role-based access control because clearance levels map to job roles.
B.It is mandatory access control because labels and clearances are enforced by the system and cannot be changed by users.
C.It is rule-based access control because classification follows written policy.
D.It is discretionary access control because document owners set the labels.
AnswerB

Mandatory access control bases every access decision on system-assigned labels compared against the subject's clearance, and users are not permitted to modify those values. Because the Restricted classification and the user clearance levels are centrally controlled and immutable to users, this arrangement is a textbook mandatory access control implementation.

Why this answer

Access decisions driven by immutable system labels compared against a subject's clearance define mandatory access control. Because users cannot alter the classification of a document or their own clearance, the system, not the owner, dictates access. Role-based and rule-based models instead key on job function or global conditions, and discretionary models allow owner control.

Exam trap

The trap here is equating written classification policy with rule-based access control, when the immutable label-versus-clearance comparison is what makes the model mandatory.

53
MCQmedium

A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:

A.Separation of duties
B.Logical access control
C.Defense in depth
D.Visitor management
AnswerD

Visitor management enforces sign-in, badge issuance and escort rules for non-employees, directly satisfying the stem's three on-premises controls. Unlike physical access systems that merely log entry, it governs the full visitor lifecycle from registration through check-out, matching the requirement that all visitors be authenticated, identifiable and supervised.

Why this answer

Visitor management encompasses the administrative and physical controls used to register, badge, and escort non-employees on premises — exactly the sign-in, badge, and escort requirements described. It is a physical security control category focused on controlling and tracking visitors.

Exam trap

CC often tests the distinction between physical and logical controls — candidates see 'sign in' and think logical access control, but the scenario describes physical visitor procedures, not system authentication.

How to eliminate wrong answers

Option A is wrong because separation of duties is a control that divides critical tasks among multiple people to prevent fraud or error — it has nothing to do with visitor sign-in or escorting. Option B is wrong because logical access control governs access to systems and data (e.g., passwords, MFA, RBAC), not physical visitor procedures. Option C is wrong because defense in depth is a layered security strategy (multiple overlapping controls), not a specific control for visitor handling — while visitor management may be part of a defense-in-depth program, the described procedures are specifically visitor management.

54
MCQeasy

Which type of access control is implemented by a cable lock attached to a laptop?

A.Administrative access control
B.Physical access control
C.Logical access control
D.Technical access control
AnswerB

A cable lock physically restrains the laptop, preventing removal of the asset itself. This satisfies the stem's requirement for a control that operates on direct physical contact with the device, rather than on logical authentication or network permissions. Physical access controls therefore mitigate theft and unauthorised hardware access, distinct from technical or administrative categories.

Why this answer

A cable lock physically tethers the laptop to a fixed object, preventing theft or physical removal of the device. Because it restricts physical contact with and movement of the asset rather than controlling logical system access, it is classified as a physical access control. Physical controls are one of the three main categories (alongside administrative and technical/logical) in the (ISC)² access control taxonomy.

Exam trap

The trap here is confusing the three access control categories — candidates see 'lock' and think of logical password locks, but a cable lock is unambiguously a physical control because it protects the hardware asset, not the data or system access.

How to eliminate wrong answers

Option A is wrong because administrative access controls are policy, procedure, and personnel-based measures such as background checks, security awareness training, and written acceptable-use policies — not hardware devices. Option C is wrong because logical (technical) access controls are software or system-enforced mechanisms such as passwords, ACLs, encryption, and biometric logon, which govern access to data and systems rather than the physical device. Option D is wrong because 'technical access control' is essentially synonymous with logical access control (e.g., firewalls, IDS, encryption) and does not describe a physical tethering device.

55
MCQmedium

A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?

A.Least privilege
B.Need-to-know
C.Separation of duties
D.Defense in depth
AnswerD

Fencing, guards, badges and biometric locks each block a different attack path, so an intruder must defeat several independent controls. This layering satisfies the stem's requirement for overlapping physical barriers, which is precisely what defence in depth means.

Why this answer

Defense in depth is the practice of layering multiple independent security controls so that if one fails, others still protect the asset. Fencing, guards, badges, and biometric locks each represent a different layer (perimeter, personnel, logical/physical entry, and biometric), and together they create overlapping protection for the server room. This layered approach is the defining characteristic of defense in depth.

Exam trap

The trap is that candidates see 'badges' and 'biometric locks' and jump to 'least privilege' or 'need-to-know' because those also involve restricting access — but the question is specifically about layering multiple controls, which is defense in depth.

How to eliminate wrong answers

Option A is wrong because least privilege means granting users only the minimum access rights needed to perform their jobs — it is about permission scope, not about layering multiple physical controls. Option B is wrong because need-to-know restricts access to information based on whether the person requires it for their role; it is an information-handling principle, not a layered physical security architecture. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error (e.g., one person initiates, another approves) — it does not describe fencing, guards, and biometric locks.

56
MCQhard

A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:

A.Password cracking
B.Unauthorized access from an unattended workstation
C.Brute force attacks
D.Shoulder surfing
AnswerB

Inactivity timeout terminates the session after a set idle period, so an unattended workstation cannot be abused by someone walking up and using the logged-in account. It directly satisfies the scenario's constraint of limiting exposure from a session left open without the user present.

Why this answer

A session timeout logs a user out after inactivity, so if they walk away from an unattended workstation, an attacker cannot continue using the already-authenticated session. This directly mitigates the risk of unauthorized physical access to a logged-in session on an unattended device.

Exam trap

CC often tests the distinction between session timeout (protects an unattended, already-authenticated session) and authentication controls like lockout or password policy (protect against guessing/cracking) — candidates confuse the two threat models.

How to eliminate wrong answers

Option A is wrong because password cracking targets stored or transmitted credentials offline/online; a session timeout does nothing to strengthen password hashing or complexity. Option C is wrong because brute force attacks involve repeatedly guessing credentials at login; session timeout does not limit login attempts or lock accounts. Option D is wrong because shoulder surfing is visual observation of someone entering credentials or data; a timeout does not prevent someone from watching the screen while the user is present.

57
MCQmedium

An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?

A.Authorization
B.Accounting
C.Authentication
D.Identification
AnswerC

Authentication is the process of verifying a claimed identity, satisfying the stem's requirement to prove the username. The password is validated against stored credentials, confirming the user is who they claim to be before any authorisation decision occurs.

Why this answer

Authentication is the process of verifying a claimed identity, typically by validating one or more factors such as something you know (password), something you have (token), or something you are (biometric). When the employee enters a password to prove the username they claimed, that verification step is authentication. Identification is the act of claiming the identity; authentication proves it.

Exam trap

The trap is conflating identification with authentication — candidates see 'username' in the question and pick identification, but the question explicitly asks about the step that proves the claimed identity, which is authentication.

How to eliminate wrong answers

Option A is wrong because authorization determines what an authenticated user is allowed to do (permissions, rights, ACLs) — it happens after authentication, not during identity proof. Option B is wrong because accounting (auditing) is the logging and tracking of user activity for later review and non-repudiation; it records what happened, it does not verify identity. Option D is wrong because identification is merely the act of claiming an identity (e.g., typing a username or swiping a badge) — it does not prove that the claim is true, which is exactly what the password step accomplishes.

58
Multi-Selecthard

A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)

Select 2 answers
A.One employee creates a purchase order, another approves it
B.Two managers must approve any payment over $5,000
C.A manager can both initiate and approve a wire transfer
D.All employees use the same password for the accounting system
E.A user has read-only access to financial reports
AnswersA, B

Splitting the purchase order creation from its approval across two employees enforces separation of duties: no single person controls the whole transaction. This directly satisfies the stem's requirement by preventing one individual from both initiating and authorising financial payments, reducing fraud risk.

Why this answer

Option A is correct because separation of duties requires that no single person controls an entire transaction; having one employee create a purchase order while a different employee approves it splits the critical functions of initiation and authorization. Option B is correct because requiring two managers to approve any payment over $5,000 enforces dual control (two-person integrity), ensuring that high-value transactions cannot be executed by one individual acting alone. Option C is incorrect because allowing a manager to both initiate and approve a wire transfer concentrates incompatible duties in one person, which is the exact opposite of separation of duties.

Option D is incorrect because sharing the same password for the accounting system destroys individual accountability and non-repudiation, and it is a poor authentication practice rather than a separation-of-duties control. Option E is incorrect because read-only access to financial reports is an example of least privilege, not separation of duties, since it does not divide transaction responsibilities among multiple people.

Exam trap

The trap is that candidates confuse separation of duties with least privilege or dual control — option E looks security-related but is least privilege, and option C is the classic 'toxic combination' that SoD is designed to prevent.

59
Multi-Selectmedium

A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)

Select 2 answers
A.Enforce password complexity requirements
B.Limit the window for session hijacking attacks
C.Provide single sign-on functionality
D.Prevent brute-force attacks on passwords
E.Reduce the risk of unauthorized access from unattended workstations
AnswersB, E

Session timeouts terminate idle authenticated sessions after a set period, shrinking the interval during which a stolen session token or cookie remains usable. This directly limits the window for session hijacking attacks, satisfying the stated security objective.

Why this answer

Option B is correct because a session timeout limits the amount of time an attacker has to reuse a stolen session token or cookie, shrinking the window during which a session hijacking attack can succeed. Option E is correct because automatically terminating idle sessions locks out anyone who approaches an unattended workstation after the legitimate user has walked away, reducing the risk of unauthorized access. Option A is incorrect because password complexity is enforced by password policy settings, not by session timeouts.

Option C is incorrect because single sign-on is provided by authentication federation technologies such as SAML, OAuth, or Kerberos, not by session expiration. Option D is incorrect because brute-force protection comes from account lockout thresholds, rate limiting, or CAPTCHA mechanisms, not from session timeouts.

Exam trap

The trap is that candidates pick 'prevent brute-force attacks' because both timeouts and lockouts relate to authentication — but brute force targets password guessing, while session timeouts target session hijacking and unattended workstation exposure.

60
Multi-Selectmedium

Which THREE are key components of Active Directory? (Select THREE.)

Select 3 answers
A.Users
B.Firewalls
C.Groups
D.LDAP
E.Organizational Units (OUs)
AnswersA, C, E

Users are a core Active Directory object class, representing identities that authenticate against a domain controller and receive access tokens. In this scenario, they satisfy the requirement for a key component, since every directory deployment stores user accounts as security principals that can be assigned permissions and group memberships.

Why this answer

Users (A) are a core Active Directory object class representing security principals that authenticate and receive permissions, so they are a key component. Groups (C) are also essential AD objects used to aggregate users and other principals for efficient permission assignment and role-based access control. Organizational Units (E) are container objects that provide the hierarchical structure for organizing users, groups, computers, and other objects, and for delegating administration and applying Group Policy.

Firewalls (B) are network security devices, not AD components, and LDAP (D) is a directory access protocol that AD supports and uses, but it is not itself a component of Active Directory.

Exam trap

CC often tests the distinction between Active Directory components and related technologies like LDAP or network devices, causing candidates to select LDAP as a component when it is actually a protocol.

61
Multi-Selectmedium

A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)

Select 2 answers
A.ABAC requires that every user be assigned exactly one static role that never changes.
B.ABAC can enforce rules such as permitting access only during business hours from a corporate network.
C.ABAC evaluates policies using attributes of the subject, the resource, the action, and the environment.
D.ABAC policies cannot incorporate data sensitivity labels because labels are a form of mandatory access control.
E.ABAC decisions are made solely from the user's job title stored in the human resources system.
AnswersB, C

Environmental attributes such as time of day and network location are first-class inputs in ABAC policy evaluation. A rule that grants access only between 08:00 and 18:00 when the request originates from the corporate network is a classic environmental condition. This illustrates how ABAC extends beyond identity alone to consider the context in which the access request occurs.

Why this answer

ABAC makes decisions by evaluating attributes of the subject, resource, action, and environment, which enables granular rules such as time-limited and location-aware access. It does not depend on a single job title, does not require one fixed role per user, and can absolutely incorporate data sensitivity labels as resource attributes. The two accurate statements describe multi-attribute evaluation and environmental conditions.

Exam trap

The trap here is assuming ABAC is just role-based access control with a different name, when its defining feature is evaluating many dynamic attributes at request time.

62
MCQeasy

A new employee at a marketing firm receives a company laptop, a proximity badge, and a one-time password token on their first day. Before being allowed to log in, the employee must enter their employee ID, then a code from the token, then scan the badge. Which access control concept does the employee ID represent in this sequence?

A.Accounting
B.Authorization
C.Authentication
D.Identification
AnswerD

Identification is the act of claiming an identity, typically by entering a username, employee ID, or similar identifier that the system can recognize. The employee ID is asserted first and then verified by the token and badge. Because the ID by itself only names who the person claims to be, it is the identification step in this access control sequence.

Why this answer

Identification is the claim of an identity, such as typing a username or employee ID, while authentication verifies that claim with credentials. In this scenario the employee ID is asserted before the token code and badge scan, so it functions as the identification step. Authorization and accounting occur only after identity is verified.

Exam trap

The trap here is assuming any credential entered during login is authentication, when the initial identifier entry is actually identification.

63
MCQeasy

An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Need-to-know
AnswerA

Fencing, bollards, lighting, guards, and biometric readers are distinct control layers, each imposing a separate obstacle before the next. An attacker must defeat all layers sequentially, which is precisely the layered, delay-and-detect approach defence in depth describes.

Why this answer

Defense in depth is a layered security strategy where multiple overlapping controls are deployed so that if one fails, others still protect the asset. The scenario shows physical perimeter controls (fencing, bollards, lighting), personnel controls (guards), and logical/physical access controls (biometric readers) — clearly multiple layers. This matches the core definition of defense in depth.

Exam trap

The trap here is confusing defense in depth with least privilege or separation of duties because all are 'security best practices' — candidates must recognize that only defense in depth describes multiple layered controls protecting the same asset.

How to eliminate wrong answers

Option B is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error by one individual — it is about role division, not layered physical and logical controls. Option C is wrong because least privilege means granting users only the minimum access needed to perform their job; the scenario describes layered barriers, not permission scoping. Option D is wrong because need-to-know restricts access to information based on job relevance, which is an information-classification principle, not a layered physical security architecture.

64
Multi-Selectmedium

Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)

Select 2 answers
A.Create a separate admin account for privileged tasks
B.Use the same account for daily work and administrative tasks
C.Disable logging for admin activities to reduce overhead
D.Implement a Privileged Access Management (PAM) solution
E.Share admin passwords among team members for convenience
AnswersA, D

Separating administrative duties from everyday user activity prevents routine browsing, email and document handling from exposing highly privileged credentials to phishing or credential theft. This directly satisfies the least-privilege and separation-of-duties requirements for privileged account management, limiting the blast radius if a standard account is compromised.

Why this answer

Option A is correct because creating a separate admin account for privileged tasks enforces separation between a user's standard daily-use account and their elevated account, so routine activities like email and web browsing cannot be leveraged to compromise administrative rights, and it enables auditing of privileged actions to a distinct identity. Option D is correct because a Privileged Access Management (PAM) solution provides vaulting, credential rotation, session brokering, just-in-time elevation, and monitoring of privileged sessions, which are core controls for reducing standing administrative access and detecting misuse. Option B is not recommended because using one account for both daily work and administrative tasks grants excessive standing privilege and exposes admin credentials to everyday attack surfaces such as phishing and malicious websites.

Option C is wrong because disabling logging for admin activities destroys the audit trail needed for accountability, incident response, and compliance, and the overhead is not a valid reason to eliminate it. Option E is wrong because sharing admin passwords among team members eliminates individual accountability, prevents effective credential rotation, and violates the principle of least privilege and non-repudiation.

Exam trap

The trap is that 'convenience' options (shared passwords, single account, disabled logging) sound efficient to busy admins, but the exam expects you to recognize they all violate core security principles of accountability, least privilege, and auditability.

65
MCQhard

A financial services firm grants tellers access to the transaction system only between 8:00 a.m. and 6:00 p.m. on business days, regardless of the teller's role. Access requests outside that window are automatically denied, and the restriction is enforced by a centrally managed policy that tellers cannot modify. Which access control approach is being applied?

A.Mandatory access control, because the system enforces the restriction without user involvement.
B.Role-based access control, because tellers form a job role that shares the same permissions.
C.Rule-based access control, because access is granted or denied according to a defined condition rather than individual identity.
D.Discretionary access control, because a manager decides which tellers receive transaction access.
AnswerC

Rule-based access control evaluates administrator-defined conditions, and the time-of-day and day-of-week window is precisely such a condition. The policy applies uniformly regardless of who the teller is, and users cannot alter it. This matches the defining characteristic of rule-based control, where objective criteria govern the decision.

Why this answer

Rule-based access control makes decisions from objective, administrator-defined conditions rather than from individual identity or job role. Restricting transaction access to a fixed time window on business days is a textbook condition, and it applies to every teller identically while remaining outside user control. The uniformity and condition-driven nature distinguish it from role-based, discretionary, and mandatory approaches.

Exam trap

The trap here is assuming that because all tellers share a job title, the control must be role-based rather than condition-driven.

66
MCQhard

A security analyst notices that an employee who transferred from Finance to Marketing still has full access to financial reporting systems six months later. The analyst wants to correct this through the access control lifecycle. Which action best addresses the root cause?

A.Require multifactor authentication for anyone accessing financial reporting systems.
B.Increase the password complexity requirement for all Finance systems.
C.Perform a periodic access review and revoke entitlements that are no longer required for the employee's current role.
D.Enable account lockout after three failed login attempts on the financial reporting systems.
AnswerC

The root cause is that permissions were never re-evaluated when the employee changed roles, a failure of the access control lifecycle. A periodic access review, sometimes called recertification, compares current entitlements against what the job now requires and removes the excess. Revoking the stale Finance rights directly corrects the excessive privilege and prevents similar drift for other transfers.

Why this answer

Excessive access after a role change is a lifecycle failure: provisioning added Finance rights, but deprovisioning or modification never removed them when the employee moved to Marketing. A periodic access review compares entitlements with current job needs and revokes what is no longer required. Authentication hardening such as complexity, lockout, or multifactor authentication protects the login but leaves the stale authorization untouched, so it cannot fix the root cause.

Exam trap

The trap here is choosing an authentication hardening control for what is actually an authorization lifecycle problem, since the account logs in legitimately but holds outdated rights.

67
MCQeasy

A hospital IT team is reviewing how staff access patient records. A nurse logs in with a unique employee ID, then enters a password plus a one-time code from a hardware token. The team wants to document which access control category this login process represents. Which category BEST describes this approach?

A.Two separate instances of something you know
B.Something you are combined with something you have
C.Something you have combined with somewhere you are
D.Something you know combined with something you have
AnswerD

The employee ID identifies the user, the password is something the nurse knows, and the one-time code from a hardware token is something the nurse has. Combining two different factors from separate categories satisfies multi-factor authentication. This accurately describes the hospital's login process and is the correct categorization.

Why this answer

Authentication factors fall into categories such as knowledge, possession, inherence, and location. The nurse's password represents knowledge, while the hardware token one-time code represents possession. Pairing factors from two different categories achieves multi-factor authentication, which is stronger than using two factors from the same category.

This combination directly matches the described login process.

Exam trap

The trap here is assuming that any two credentials count as multi-factor authentication when they may belong to the same factor category.

68
MCQhard

In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

A.Container Name
B.Common Name
C.Country Name
D.Context Name
AnswerB

CN is the attribute naming the entry itself within its container, holding the object's common name — here "John Smith". The stem's DN places CN as the leftmost, most specific relative distinguished name, with OU and DC components locating it hierarchically, so CN satisfies the question's request for the abbreviation's meaning.

Why this answer

In LDAP Distinguished Names (DNs), CN stands for Common Name, which identifies the specific object or entity within the directory hierarchy — in this case, the user 'John Smith'. LDAP DNs are read right-to-left, with the most specific attribute (CN) appearing first and the root domain components (DC) appearing last. CN is one of the most frequently used RDN (Relative Distinguished Name) attributes for naming users, groups, and other objects.

Exam trap

The trap here is that candidates confuse CN with other LDAP attributes like C (Country) or OU (Organizational Unit), or assume CN is a generic 'Container Name' — the exam tests whether you know the exact X.500 attribute abbreviations used in Distinguished Names.

How to eliminate wrong answers

Option A is wrong because 'Container Name' is not an LDAP attribute — containers are represented by OU (Organizational Unit) or other object classes, not CN. Option C is wrong because 'Country Name' is represented by the C attribute (e.g., C=US) in an LDAP DN, not CN. Option D is wrong because 'Context Name' is not a valid LDAP naming attribute; it is a fabricated term that does not exist in the X.500/LDAP schema.

69
Multi-Selecthard

A defense contractor runs a facility where entry to the secure lab requires a fingerprint scan, and entry to the adjacent server cage additionally requires a retina scan. A security analyst is documenting the access control design for an audit. Which two statements accurately describe these controls? (Choose two.)

Select 2 answers
A.The fingerprint and retina scans together demonstrate the principle of least privilege.
B.The fingerprint scan at the lab door is a biometric control that verifies a physiological characteristic of the individual.
C.The retina scan for the server cage is an inherence factor because it verifies a physical characteristic of the analyst.
D.Requiring both the fingerprint and retina scans for the server cage is an example of multifactor authentication.
E.Because both doors use biometrics, the facility has satisfied the requirement for two-factor authentication.
AnswersB, C

Fingerprint recognition measures a physiological trait, which classifies it as a biometric control. Because the scan is matched against an enrolled template to confirm the person's claimed identity, it functions as an authentication mechanism at the lab entrance, satisfying the requirement that a biometric verifies something the individual is.

Why this answer

Fingerprint and retina scans both measure physical characteristics of a person, so each is a biometric and an inherence factor. Pairing them strengthens verification but does not create multifactor authentication, because multifactor requires factors from separate categories such as knowledge, possession, and inherence. Least privilege concerns granted permissions, not the credentials presented at a door.

Exam trap

The trap here is counting two different biometric methods as two authentication factors, when both belong to the single inherence category.

70
Multi-Selecthard

A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)

Select 2 answers
A.Biometric reader on server room door
B.Cable locks on laptops
C.Session timeout settings
D.Password complexity policy
E.Role-based access control (RBAC)
AnswersA, B

A biometric reader authenticates identity through fingerprint or iris traits before granting entry, directly controlling who physically passes through the server room door. It is a preventive physical control restricting human access to the facility.

Why this answer

Option A (biometric reader on server room door) is correct because a biometric reader is a physical authentication mechanism that verifies a person's fingerprint, iris, or other biological trait before granting entry to the server room, making it a classic physical access control. Option B (cable locks on laptops) is correct because a cable lock is a physical restraint that tethers a laptop to a fixed object, deterring theft and unauthorized physical removal of the device. Option C (session timeout settings) is incorrect because it is a logical/technical control that terminates idle sessions, not a physical barrier.

Option D (password complexity policy) is incorrect because it is an administrative/logical control governing credential strength. Option E (role-based access control) is incorrect because RBAC is a logical access control model that grants permissions based on job roles, not physical access.

Exam trap

The trap is conflating logical access controls (RBAC, password policy, session timeout) with physical ones; candidates often select RBAC because it contains the word 'access,' but the question specifically asks for physical controls.

71
MCQmedium

An account lockout policy is implemented to protect against which type of attack?

A.Brute force
B.Man-in-the-middle
C.Social engineering
D.Phishing
AnswerA

An account lockout policy locks an account after a set number of failed authentication attempts, directly thwarting brute force attacks that rely on repeated password guessing. It satisfies the stem by halting the automated trial-and-error process before credentials are discovered.

Why this answer

An account lockout policy locks an account after a specified number of failed login attempts (e.g., 5 attempts), which directly thwarts brute-force attacks that rely on trying many password combinations. By locking the account, the attacker is prevented from continuing automated guessing, and the legitimate user or admin is alerted. This is the primary defensive purpose of account lockout.

Exam trap

The trap is that phishing and brute force both involve credential theft, but only brute force relies on repeated login attempts that lockout can stop — phishing yields valid credentials on the first try, bypassing lockout entirely.

How to eliminate wrong answers

Option B is wrong because man-in-the-middle attacks intercept communications between two parties (e.g., via ARP spoofing or rogue Wi-Fi) — account lockout does nothing to prevent session interception. Option C is wrong because social engineering manipulates people into revealing information or performing actions; lockout policies don't address human manipulation. Option D is wrong because phishing is a form of social engineering that tricks users into entering credentials on fake sites — the credentials are valid, so lockout won't trigger; anti-phishing requires user training, email filtering, and MFA.

72
Multi-Selecthard

A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)

Select 2 answers
A.It requires every service to maintain a local copy of all domain user passwords.
B.It provides mutual authentication, allowing both the client and the service to verify each other's identity.
C.It stores user passwords in a reversible encrypted format inside each service ticket.
D.It uses a trusted third party called the Key Distribution Center to issue tickets.
E.It transmits the user's password to each service in plaintext during authentication.
AnswersB, D

Kerberos supports mutual authentication because the service ticket is encrypted with the service's secret key, proving the ticket came from the Key Distribution Center, while the authenticator proves the client holds the session key. This lets both parties verify each other, which is valuable in domain environments where clients must be sure they are contacting a legitimate service and not an impostor.

Why this answer

Kerberos uses a trusted Key Distribution Center to issue ticket-granting and service tickets, and it supports mutual authentication because the service ticket is encrypted with the service key while the client's authenticator proves possession of the session key. Passwords are never sent to services or embedded in tickets, which is why the two selected characteristics accurately describe the protocol.

Exam trap

The trap here is assuming that because tickets grant access, they must carry the user's password, when in fact Kerberos deliberately keeps passwords out of tickets and off the wire.

73
MCQmedium

A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?

A.Kerberos ticket granting
B.Remote Authentication Dial-In User Service (RADIUS)
C.Security Assertion Markup Language (SAML)
D.Lightweight Directory Access Protocol (LDAP) bind
AnswerC

SAML is an XML-based federation standard where an identity provider sends signed assertions to service providers, enabling single sign-on. The scenario's central identity provider asserting identity to email, code repository, and expense applications matches SAML's identity provider and service provider model, making this the correct technology.

Why this answer

Federation allows one trusted identity provider to authenticate a user and send signed assertions to multiple service providers, delivering single sign-on across separate systems. SAML is the standard that defines these assertions and the request-response flow. The described environment, where one login grants access to email, code repository, and expense applications, is a textbook SAML federation deployment.

Exam trap

The trap here is treating any single sign-on technology as interchangeable, when the identity provider asserting identity to separate applications specifically indicates federation.

74
MCQmedium

In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?

A.Organizational Units (OUs)
B.Group Policy Objects (GPOs)
C.Domain controllers
D.LDAP
AnswerA

Organizational Units are containers within Active Directory that hold users, groups and computers hierarchically, letting administrators link Group Policy Objects at specific levels. This hierarchical structure satisfies the stem's requirement for organising directory objects so policies apply appropriately.

Why this answer

Organizational Units (OUs) are the container objects within Active Directory that provide the hierarchical structure used to organize users, groups, computers, and other objects. Because Group Policy can be linked directly to an OU, it is the primary mechanism for scoping policy application to a subset of the directory. This makes OUs the correct answer for organizing objects hierarchically for policy purposes.

Exam trap

The trap here is confusing the container (OU) with the policy content (GPO) or the protocol (LDAP); candidates often pick GPO because the question mentions policies, missing that the question asks what organizes objects hierarchically.

How to eliminate wrong answers

Option B is wrong because Group Policy Objects are the policy definitions themselves, not the containers that organize directory objects — GPOs are linked to sites, domains, or OUs. Option C is wrong because domain controllers are servers that host the AD database and authenticate users, not organizational containers. Option D is wrong because LDAP is an access protocol used to query and modify directory services, not a hierarchical organizational component within AD.

75
MCQhard

A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?

A.Excessive privilege because engineers can manage production databases
B.Lack of accountability because shared credentials prevent tracing actions to an individual
C.Missing authorization because the account was never formally approved
D.Weak authentication because the shared account uses only a single password
AnswerB

Accountability requires that every action can be attributed to a specific identity through unique credentials and audit logs. When several engineers share one privileged account, the logs record only the shared identity, so no one can be held responsible for a given change, which is exactly the control failure the audit identified.

Why this answer

Accountability depends on unique identities so that logs can tie each action to one person. Sharing a single privileged credential collapses multiple engineers into one identity, making attribution impossible and undermining nonrepudiation. The remedy is individual named accounts with privileged access management, not merely stronger authentication or additional approvals.

Exam trap

The trap here is focusing on the password strength of the shared account, when the real defect is that one credential destroys individual attribution.

Page 1 of 2 · 146 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Access Controls Concepts questions.