Authorization & Access Control Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Authorization & Access Control flashcards as text
Which access control mechanism allows the owner of a resource to grant access to other users at their own discretion?
Answer: Discretionary Access Control (DAC)
In DAC, the resource owner has discretion to grant or revoke access to other subjects, such as file owners setting permissions in traditional OS environments.
A policy requiring users to log in with separate accounts for administrative versus regular tasks best implements which principle?
Answer: Least privilege
Using separate accounts for privileged and regular work limits the exposure of elevated privileges by applying least privilege to each session.
In the Bell-LaPadula model, the '*-property' (star property) rule states that a subject:
Answer: Cannot write data to a lower classification level
The *-property prevents write-down, ensuring classified information cannot flow to lower classification levels where it shouldn't be accessible.
Which of the following is a key difference between authentication and authorization?
Answer: Authentication verifies identity; authorization determines what actions are permitted
Authentication establishes identity (who you are), while authorization determines what that authenticated identity is allowed to do.
An access control matrix row represents a subject's permissions. What does each column represent?
Answer: Permissions for a specific object or resource
In an access control matrix, columns represent objects (resources), and each cell specifies the access rights a subject has to that object.
Which access control concept is most directly implemented by a firewall's rule set that permits or denies traffic based on IP and port?
Answer: Rule-Based Access Control
Rule-Based Access Control uses predefined rules (such as firewall ACLs) to permit or deny access based on conditions like source IP, destination port, and protocol.
In a CAP context, which document formally establishes the boundary of an authorization decision for an information system?
Answer: Authorization Boundary document
The authorization boundary defines the scope of the information system for which the Authorizing Official (AO) grants an Authority to Operate (ATO).