Courseiva

CCNA Access Controls Questions

25 of 100 questions · Page 2/2 · Access Controls · Answers revealed

76
MCQhard

An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?

A.Kerberos
B.SAML
C.OAuth 2.0
D.OpenID Connect
AnswerB

SAML exchanges XML-based assertions between identity and service providers, enabling browser-based single sign-on across security domains. It directly satisfies the stem's requirement for federated authentication using corporate credentials at a partner's cloud application, with the identity provider issuing signed assertions the partner's application validates and trusts.

Why this answer

SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on. It is specifically designed for federated identity scenarios where users authenticate with their corporate credentials to access partner cloud applications. The requirement for XML-based assertions directly points to SAML.

Exam trap

The trap is confusing authentication with authorization: OAuth 2.0 is often mistakenly chosen for SSO, but it is an authorization framework, while SAML is the XML-based authentication standard for federated SSO.

How to eliminate wrong answers

Option A is wrong because Kerberos is a ticket-based authentication protocol used primarily within a Windows domain or trusted realm, not for cross-organizational federated SSO with XML assertions. Option C is wrong because OAuth 2.0 is an authorization framework for delegated access, not an authentication protocol, and it does not use XML assertions. Option D is wrong because OpenID Connect is an authentication layer built on OAuth 2.0 that uses JSON Web Tokens (JWT), not XML-based assertions.

77
MCQhard

A financial institution uses a RADIUS server for centralized authentication of its VPN users. A security administrator notices that authentication requests from a new VPN concentrator are being rejected, while requests from other devices work fine. The RADIUS server logs show that the shared secret does not match. What is the most likely cause?

A.The RADIUS server's certificate has expired.
B.The user accounts are not configured with the correct password policy.
C.The VPN concentrator is not included in the RADIUS server's list of authorized clients.
D.The VPN concentrator is configured with the wrong shared secret.
AnswerD

RADIUS clients and servers authenticate each other using a shared secret. If the shared secret on the VPN concentrator does not match the one configured on the RADIUS server, authentication requests will be rejected. The logs indicating a shared secret mismatch point directly to this configuration error on the new device.

Why this answer

RADIUS uses a shared secret between the client (VPN concentrator) and the server to authenticate and encrypt certain attributes. When the shared secret does not match, the server rejects requests from that client. The logs explicitly indicate a shared secret mismatch, so the most likely cause is that the new VPN concentrator has been configured with an incorrect shared secret.

Other options would produce different symptoms or logs.

Exam trap

The trap here is assuming that any authentication failure is due to user credentials or certificates, when the specific log message points to a device-level shared secret mismatch.

78
MCQmedium

An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?

A.Session key
B.Ticket-Granting Ticket (TGT)
C.Service ticket
D.Authentication Server (AS) reply
AnswerB

The Ticket-Granting Ticket is obtained at initial authentication and used to request service tickets. If it expires, subsequent access to the network share fails with a ticket expired error, matching the stem's symptom after password entry.

Why this answer

The Ticket-Granting Ticket (TGT) has a limited lifetime (typically 8-10 hours). When it expires, the user must re-authenticate to get a new TGT.

79
MCQmedium

A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?

A.Need-to-know
B.Separation of duties
C.Least privilege
D.Accountability
AnswerC

Least privilege requires granting only the access needed to perform a role's duties. A service account holding domain administrator rights far exceeds its operational requirements, so the excessive privilege violates that principle, regardless of authentication or separation-of-duties controls.

Why this answer

Granting a service account domain administrator privileges violates the principle of least privilege, which states that accounts should have only the minimum permissions necessary to perform their required tasks. A service account typically needs limited, specific permissions, not full domain admin rights. This over-provisioning increases the attack surface and risk.

Exam trap

SSCP often tests the distinction between least privilege and need-to-know, causing candidates to choose need-to-know when the issue is excessive permissions rather than information access.

How to eliminate wrong answers

Option A is wrong because need-to-know is about limiting access to information based on job requirements, not about the level of privileges granted. Option B is wrong because separation of duties involves dividing tasks among multiple people to prevent fraud, which is not directly violated by granting excessive privileges to a single account. Option D is wrong because accountability refers to tracing actions to a specific individual, which is a logging/auditing concern, not the principle violated by excessive permissions.

80
MCQhard

An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?

A.Password expiry
B.Password length
C.Password history
D.Password complexity
AnswerC

Password history enforces the no-reuse constraint by storing hashes of prior passwords and rejecting any new one matching the last 10 entries. This directly satisfies the stem's requirement that users cannot reuse recent passwords, distinct from complexity, length, or expiry settings.

Why this answer

The requirement that users cannot reuse any of the last 10 passwords is specifically addressing password history, which prevents users from cycling back to previous passwords. This element enforces a memory of past passwords to avoid reuse.

Exam trap

The trap is confusing password history with password expiry or complexity; candidates might think 'cannot reuse' relates to expiry, but it's specifically about remembering past passwords.

How to eliminate wrong answers

Option A is wrong because password expiry refers to the maximum age of a password before it must be changed, such as the 90-day requirement. Option B is wrong because password length refers to the minimum number of characters, such as the 12-character requirement. Option D is wrong because password complexity refers to the mix of character types (uppercase, lowercase, digits, special characters).

81
MCQmedium

A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?

A.Authorization
B.Identification
C.Authentication
D.Accountability
AnswerC

Authentication is the process of verifying a claimed identity by checking the supplied credential against the stored one. Here, the system compares the password against the record for 'jsmith', confirming the user is who they claim to be. This directly satisfies the stem's requirement to verify the password matches the one on file.

Why this answer

Authentication is the process of verifying a claimed identity — here, validating that the password provided matches the stored credential for 'jsmith'. Identification is the act of claiming an identity (e.g., entering a username), while authentication proves it. The question explicitly describes verification of the password, which is authentication.

Exam trap

SSCP often tests the distinction between identification (claiming an identity) and authentication (proving it), and between authentication and authorization (what you can do), causing candidates to pick the wrong stage in the identity lifecycle.

How to eliminate wrong answers

Option A is wrong because authorization determines what an authenticated user is allowed to do (permissions, access rights), not whether the password is correct. Option B is wrong because identification is merely the claim of identity (e.g., typing 'jsmith'), which occurs before authentication and does not verify anything. Option D is wrong because accountability is the ability to trace actions to a specific user via logs and audit trails — it depends on authentication but is not the verification step itself.

82
MCQeasy

Which of the following is the correct order of the access control process?

A.Identification, authentication, authorization, accountability
B.Identification, authorization, authentication, accountability
C.Authorization, authentication, identification, accountability
D.Authentication, identification, authorization, accountability
AnswerA

Access control proceeds by first claiming an identity, then proving it, then granting rights, then logging activity. Accountability depends on the prior identification and authentication steps, so this sequence reflects the actual dependency chain rather than any reordering of the four stages.

Why this answer

The access control process begins with identification, where a subject claims an identity (e.g., username). Next is authentication, verifying that identity (e.g., password). Then authorization determines what resources the authenticated subject can access.

Finally, accountability involves logging and auditing actions to hold the subject responsible. This sequence is fundamental in security models.

Exam trap

The trap is mixing up the order of authentication and authorization; candidates might think authorization comes before authentication, but you cannot authorize an unauthenticated identity.

How to eliminate wrong answers

Option B is wrong because authorization cannot occur before authentication; you must verify identity before granting access. Option C is wrong because authorization and authentication are reversed; identification must come first. Option D is wrong because authentication cannot precede identification; you need to claim an identity before verifying it.

83
MCQmedium

A healthcare organization must enforce access control based on a combination of the user's assigned department, the classification of the data being accessed, and the time of day. Users in the cardiology department may view patient records only during their scheduled shift, and only if the record belongs to a patient currently admitted to cardiology. Which access control model BEST supports these requirements?

A.Role-Based Access Control (RBAC)
B.Attribute-Based Access Control (ABAC)
C.Discretionary Access Control (DAC)
D.Mandatory Access Control (MAC)
AnswerB

ABAC evaluates attributes of the subject, object, action, and environment, which maps directly to department, data classification, time of day, and patient admission status. Policies written as boolean rules can require all conditions to be true before granting access, delivering the fine-grained, context-aware decisions this scenario demands. This makes ABAC the appropriate model for combining multiple dynamic factors into one authorization decision.

Why this answer

Attribute-Based Access Control is designed for policy decisions that combine multiple characteristics of the user, the resource, and the environment. Department, data classification, shift time, and a patient's current admission status are all attributes that can be evaluated in a single rule, so access is granted only when every condition is satisfied. The other models rely on ownership, static labels, or roles that cannot express these dynamic, contextual constraints together.

Exam trap

The trap here is assuming that role membership alone is sufficient for context-sensitive access, when in fact temporal and data-context conditions require attribute-based evaluation.

84
MCQmedium

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

A.Mandatory Access Control (MAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Role-Based Access Control (RBAC)
AnswerB

DAC grants the resource owner discretion over access decisions, so they assign permissions directly to other subjects. This owner-controlled permission assignment is precisely the mechanism the stem requires, distinguishing DAC from mandatory and role-based models where policy or roles dictate access.

Why this answer

Discretionary Access Control (DAC) gives resource owners discretion to grant or deny access to others.

85
MCQeasy

A security analyst is reviewing authentication logs and notices that a user account was used to log in from two different geographic locations within a five-minute window. The organization uses a centralized RADIUS server for authentication. Which of the following should the analyst investigate FIRST to determine if this is a legitimate concurrent session or a compromise?

A.Examine the firewall rules governing RADIUS traffic.
B.Check the user's group membership in Active Directory.
C.Review the user's password complexity policy.
D.Check the RADIUS server's accounting logs for session start and stop records.
AnswerD

RADIUS accounting logs record session start and stop times, as well as the network access server and assigned IP address. Reviewing these logs first can reveal whether two simultaneous sessions were actually established and from which devices. This directly addresses whether the logins are concurrent and helps distinguish a legitimate session from credential theft.

Why this answer

RADIUS accounting logs provide session start and stop records, including the network access server and assigned IP address. These details allow the analyst to verify whether two sessions were truly concurrent and from which locations. Other options relate to policy or authorization and do not provide session-specific evidence needed to investigate the suspicious logins.

Exam trap

The trap here is focusing on password or group policy instead of session accounting data, which is the only source that can confirm concurrent logins.

86
Multi-Selectmedium

A security team is hardening a centralized authentication service and wants to reduce the risk of credential replay and lateral movement if a password is compromised. Which TWO of the following controls directly support this goal? (Choose two.)

Select 2 answers
A.Enforce a maximum password age of 60 days
B.Implement just-in-time privileged access with short-lived credentials
C.Increase the minimum password length to 16 characters
D.Publish a quarterly security awareness newsletter
E.Require multi-factor authentication for all interactive logins
AnswersB, E

Just-in-time privileged access issues credentials only when needed and for a brief window, so a captured credential quickly becomes useless and cannot be replayed later. This shrinks the attack surface for lateral movement because standing privileges do not persist across the environment. It directly supports the goal of reducing replay risk and containing a compromised password.

Why this answer

Reducing replay and lateral movement risk requires controls that make a stolen password insufficient on its own and that limit how long any credential remains usable. Multi-factor authentication forces an additional factor beyond the password, and just-in-time privileged access with short-lived credentials ensures captured secrets expire quickly. Together they directly counter replay and constrain an attacker's ability to move through the environment.

Exam trap

The trap here is treating password length or rotation as defenses against replay, when those controls only affect guessing and cracking difficulty, not the reuse of an already-valid credential.

87
MCQhard

In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?

A.The IdP hosts the application and enforces access control policies
B.The IdP validates the user's OTP token
C.The IdP generates a Kerberos ticket for the user
D.The IdP authenticates the user and issues a SAML assertion to the SP
AnswerD

In SAML federation the IdP owns authentication, verifying the user's credentials and then issuing a signed assertion describing the authenticated subject. The SP trusts that assertion to grant access, so the IdP never authorises resources itself.

Why this answer

The IdP authenticates the user and issues a SAML assertion containing identity attributes and authorization claims. The SP trusts this assertion to grant access without re-authenticating the user.

88
Multi-Selecthard

An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)

Select 3 answers
A.Fail-open
B.Least privilege
C.Need-to-know
D.Separation of duties
E.Defense in depth
AnswersB, C, D

Least privilege grants each user only the minimum access rights required to perform their role, reducing the blast radius of compromised accounts or insider misuse. It is fundamental because the access control policy must limit permissions by default rather than granting broad standing access.

Why this answer

Option B (Least privilege) is correct because users and processes should be granted only the minimum access rights necessary to perform their assigned tasks, reducing the attack surface and limiting damage from compromised accounts. Option C (Need-to-know) is correct because access to specific information should be restricted to individuals who require it to fulfill their job responsibilities, which is a foundational access control principle closely tied to least privilege. Option D (Separation of duties) is correct because splitting critical tasks among multiple users prevents any single person from having enough control to commit fraud or cause significant harm without detection, a core principle in access control policy design.

Option A (Fail-open) is not a fundamental access control principle; fail-open means a system defaults to allowing access when it fails, which is generally a security weakness rather than a policy principle. Option E (Defense in depth) is a valid security architecture concept involving layered controls, but it is not one of the three fundamental access control principles being asked for here.

Exam trap

SSCP often tests whether candidates can distinguish fundamental access control principles (least privilege, need-to-know, separation of duties) from broader security strategies (defense in depth) or insecure failure modes (fail-open).

89
MCQmedium

An IT administrator needs to deprovision a user who has been terminated. Which of the following actions should be performed first to ensure security?

A.Remove the user from all groups
B.Delete the user account
C.Disable the user account
D.Change the user's password
AnswerC

Disabling the account immediately blocks authentication and access while preserving the object and its group memberships for audit and possible rehire. This satisfies the security-first constraint, since deletion would remove evidence and any dependent access before revocation is verified.

Why this answer

Immediately disabling the account prevents any further access. Evidence preservation can be done afterward, and deletion should be delayed until necessary.

90
MCQmedium

An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?

A.To encrypt all network traffic
B.To obtain service tickets for accessing resources
C.To provide a digital signature for emails
D.To authenticate the user to the network
AnswerB

The TGT is issued by the Authentication Service after initial credential validation and is presented to the Ticket Granting Service to request service tickets. It proves the user's identity without re-entering credentials, enabling single sign-on for subsequent resource access.

Why this answer

The TGT is obtained from the Authentication Server (AS) and is used to request service tickets from the Ticket Granting Server (TGS) without re-entering credentials, enabling SSO.

91
MCQmedium

Which of the following best describes the concept of accountability in access controls?

A.Users must present multiple factors to gain access
B.Users must be uniquely identified and their actions logged
C.The system must verify the user's identity before granting access
D.The resource owner can delegate access to others
AnswerB

Accountability requires that each user be uniquely identified so actions can be traced back to a specific individual, with those actions recorded in logs. Shared or generic accounts break this, since activity cannot be attributed to one person.

Why this answer

Accountability in access control means that every action can be traced back to a uniquely identified individual, which requires both unique identification (no shared accounts) and logging of activity. This is what allows an organization to hold a specific person responsible for what was done with their credentials. It is distinct from authentication (proving identity) and authorization (what you're allowed to do).

Exam trap

SSCP often tests the distinction between authentication, authorization, and accountability — candidates frequently pick the authentication option (C) because it sounds like the 'security' answer, but accountability specifically requires unique identification plus logging, not just identity verification.

How to eliminate wrong answers

Option A is wrong because requiring multiple factors describes multi-factor authentication (MFA), which is an authentication strength control, not accountability. Option C is wrong because verifying identity before granting access describes authentication, which is a prerequisite for accountability but does not by itself provide it. Option D is wrong because delegating access describes authorization administration by a resource owner, which is a permission-management activity, not accountability.

92
Multi-Selectmedium

A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)

Select 2 answers
A.Discretionary access control
B.Separation of duties
C.Need to know
D.Mandatory access control
E.Least privilege
AnswersB, E

Splitting the medication workflow so no single user both orders and approves it enforces separation of duties, preventing one person from completing a sensitive transaction end to end. This satisfies the stem's explicit constraint that ordering and administration approval must remain with different individuals.

Why this answer

Least privilege ensures users have only the permissions needed (nurse view, doctor view/update). Separation of duties prevents a single user from performing conflicting actions (order and approve).

93
Multi-Selectmedium

An organization is implementing a privileged access management (PAM) solution. Which THREE of the following are common PAM capabilities?

Select 3 answers
A.Just-in-time (JIT) provisioning of privileged access
B.Single sign-on for all applications
C.Password vaulting for storing privileged credentials securely
D.Self-service password reset for end users
E.Recording and monitoring of privileged sessions
AnswersA, C, E

Just-in-time provisioning grants elevated rights only for a defined window, then revokes them automatically, directly satisfying PAM's need to eliminate standing privileges. This contrasts with permanent admin accounts, which persist indefinitely and widen the attack surface. JIT is a core PAM capability alongside credential vaulting and session recording.

Why this answer

PAM includes password vaulting, session recording, and just-in-time provisioning to secure privileged accounts.

94
MCQhard

A hospital uses a discretionary access control model on its file shares. A department head grants a colleague read access to a folder containing protected health information so they can cover a vacation. Months later an audit finds the access still active after the coverage ended. Which characteristic of discretionary access control most directly explains why this happened?

A.Permissions are derived from the user's job role rather than from individual grants.
B.Access decisions are enforced by system-wide labels that owners cannot override.
C.Resource owners can grant access at their own discretion, and no central authority automatically removes it.
D.The system enforces a strict need-to-know policy using centralized administration.
AnswerC

In discretionary access control the owner of a resource decides who receives access, and the system does not inherently revoke that access when the business need ends. Because the department head acted as owner and no centralized lifecycle process intervened, the permission persisted after the vacation coverage concluded. This decentralization of authority is the defining trait that produced the stale entitlement found during the audit.

Why this answer

Discretionary access control places grant authority with resource owners, which is flexible but creates lifecycle risk because nothing forces revocation when the original justification disappears. The stale protected health information access persisted until an audit surfaced it. Recognizing this characteristic explains why the hospital needs centralized entitlement review, time-bound access requests, and automated revocation rather than simply retraining the department head.

Exam trap

The trap here is blaming the user for forgetting to revoke access, when the real cause is the model's decentralized owner-controlled grants.

95
MCQmedium

A company uses discretionary access control (DAC) for its file shares. A project manager creates a folder and wants to grant a team member read-only access. Which of the following best describes how access is determined in this model?

A.The team member must request access through a centralized approval workflow.
B.The project manager, as the owner of the folder, can set the permissions for the team member.
C.The team member's access is determined by their role in the organization.
D.The system administrator must assign a label to the folder and the user's clearance.
AnswerB

In discretionary access control, the owner of a resource has the discretion to grant or revoke access. Since the project manager created the folder, they are the owner and can assign read-only permission to the team member. This is the defining characteristic of DAC.

Why this answer

Discretionary access control (DAC) is characterized by the owner of the resource having the ability to determine who can access it and with what permissions. In this scenario, the project manager owns the folder and can grant read-only access to the team member. The other options describe characteristics of MAC, RBAC, or administrative approval processes, which are not inherent to DAC.

Exam trap

The trap here is confusing DAC with RBAC or MAC, assuming that access is determined by roles or labels rather than by the resource owner's discretion.

96
MCQeasy

Which access control model allows the owner of a resource to determine who can access it and what privileges they have?

A.Mandatory Access Control (MAC)
B.Attribute-Based Access Control (ABAC)
C.Discretionary Access Control (DAC)
D.Role-Based Access Control (RBAC)
AnswerC

Discretionary Access Control satisfies the stem's requirement that a resource owner assigns permissions, since DAC grants each owner discretion over their own objects via access control lists. Unlike mandatory or role-based models, where central policy or job function dictates access, DAC places that authority directly with the owner.

Why this answer

DAC (Discretionary Access Control) is defined by the resource owner having discretion over who can access the resource and what permissions they receive. In DAC systems, ownership is the basis for control — the owner can grant, revoke, or modify access rights at will, typically via ACLs. This owner-driven discretion is the defining characteristic that separates DAC from the other models.

Exam trap

SSCP often tests the distinction between who controls access — the owner (DAC), the system/labels (MAC), the role (RBAC), or attributes/policy (ABAC) — so candidates who focus on 'how access is checked' rather than 'who decides' pick the wrong model.

How to eliminate wrong answers

Option A is wrong because MAC enforces access decisions based on system-assigned labels (e.g., Bell-LaPadula sensitivity levels) and the owner cannot override those policy decisions. Option B is wrong because ABAC evaluates attributes of subjects, objects, and environment against policy rules — access is determined by policy evaluation, not by owner discretion. Option D is wrong because RBAC grants access based on the subject's assigned role within the organization, not on ownership of the resource.

97
Multi-Selecteasy

A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?

Select 2 answers
A.Permissions are assigned to roles.
B.Access rules are defined by the system, not users.
C.Users can grant access to other users.
D.Subjects and objects have security labels.
E.Access is based on the owner's discretion.
AnswersB, D

Mandatory Access Control enforces access decisions through a central authority using security labels and clearances, so users cannot alter permissions themselves. This satisfies the high-security constraint, where only the system assigns sensitivity labels and determines access, preventing user discretion or ownership-based control that discretionary models permit.

Why this answer

MAC uses labels for subjects and objects, and access decisions are based on clearance and classification. Users cannot change permissions.

98
MCQhard

An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?

A.Session recording
B.Just-in-time provisioning
C.Password vaulting
D.Role mining
AnswerB

Just-in-time provisioning grants elevated privileges only for the duration of a specific task, then revokes them automatically. This directly satisfies the PAM requirement for temporary administrative rights issued on demand, eliminating standing access. Unlike permanent role assignment, it enforces least privilege by limiting the exposure window during which credentials could be abused.

Why this answer

Just-in-time (JIT) provisioning grants elevated privileges only for the duration they are needed, then automatically revokes them. This directly matches the requirement of temporary administrative rights granted on demand. It reduces standing privilege and the window of exposure if credentials are compromised.

Exam trap

SSCP often tests the distinction between PAM capabilities that manage credentials (vaulting), audit sessions (recording), or analyze roles (mining) versus those that actually grant time-bound access (JIT) — candidates who focus on 'privileged access' broadly pick the wrong capability.

How to eliminate wrong answers

Option A is wrong because session recording captures and audits privileged sessions for compliance and forensics — it does not grant temporary rights. Option C is wrong because password vaulting stores and checks out privileged credentials securely; it manages secrets but does not by itself provide time-bound elevation. Option D is wrong because role mining analyzes existing entitlements to help design roles — it is an analytics/design activity, not a runtime privilege-granting capability.

99
MCQmedium

Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?

A.Kerberos
B.OAuth 2.0
C.OpenID Connect
D.SAML
AnswerD

SAML satisfies the cross-domain single sign-on requirement by exchanging XML-based assertions between an identity provider and service provider. Its assertion format carries authentication and attribute statements, enabling federated trust across separate security domains without sharing credentials, which matches the stem's specified XML assertion and SSO constraints precisely.

Why this answer

SAML (Security Assertion Markup Language) is an XML-based federated identity protocol that uses assertions to convey authentication and authorization information between identity providers and service providers. It enables single sign-on across different security domains by allowing a user authenticated at one domain to access resources in another without re-authenticating.

Exam trap

SSCP often tests whether candidates confuse SAML (XML-based, authentication/SSO) with OAuth 2.0 (JSON-based, authorization) and OpenID Connect (JSON/JWT-based, authentication layer on OAuth), so the XML assertion detail is the key discriminator.

How to eliminate wrong answers

Option A is wrong because Kerberos is a ticket-based authentication protocol that uses symmetric key cryptography and does not use XML assertions; it operates within a realm and is not typically described as a federated identity protocol for cross-domain SSO in the web sense. Option B is wrong because OAuth 2.0 is an authorization framework, not an authentication protocol, and it uses JSON tokens (access tokens), not XML assertions. Option C is wrong because OpenID Connect is built on OAuth 2.0 and uses JSON Web Tokens (JWTs), not XML assertions, for identity information.

100
MCQeasy

A small business owner wants to implement access control for a shared folder on a Windows server. The owner wants to grant different permissions to individual employees based on their specific job duties, without creating groups. Which access control model is most appropriate?

A.Discretionary access control (DAC)
B.Attribute-based access control (ABAC)
C.Role-based access control (RBAC)
D.Mandatory access control (MAC)
AnswerA

DAC allows the owner of a resource to grant permissions to individual users at their discretion. This matches the owner's requirement to assign different permissions to employees based on job duties without using groups. DAC is the most appropriate model here.

Why this answer

Discretionary access control (DAC) is the model where the owner of a resource determines who can access it and with what permissions. In this scenario, the small business owner wants to grant individual permissions to employees based on their job duties without creating groups. DAC allows this flexibility.

RBAC would require roles, MAC uses labels, and ABAC uses attributes, all of which are more complex or not aligned with the owner's direct control.

Exam trap

The trap here is overcomplicating the solution by choosing a more complex model like ABAC or RBAC, when the simple requirement points to DAC.

← PreviousPage 2 of 2 · 100 questions total

Ready to test yourself?

Try a timed practice session using only Access Controls questions.