Authorization & Access Control Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Authorization & Access Control flashcards as text
Which NIST SP 800-53 control family is most directly associated with managing access to information and systems?
Answer: Access Control (AC)
The Access Control (AC) family in NIST SP 800-53 contains controls directly governing who can access information systems and under what conditions.
A user is given temporary elevated access to deploy a change and the access is automatically revoked after 4 hours. This is an example of:
Answer: Time-based access control / just-in-time access
Just-in-time (JIT) or time-based access control grants elevated privileges only for the duration needed and automatically removes them afterward.
Which principle dictates that a user should only be able to access information that is relevant to their current task, even if they are cleared for a higher classification level?
Answer: Need to know
Need to know restricts access to information based on job relevance, regardless of the user's clearance level.
Which access control model was specifically designed to enforce confidentiality in military and government information systems?
Answer: Bell-LaPadula Model
The Bell-LaPadula model enforces confidentiality by preventing read-up and write-down, making it foundational for classified military and government systems.
An employee transfers to a new department but retains all access rights from their previous role in addition to their new ones. This risk is known as:
Answer: Privilege creep (access accumulation)
Privilege creep occurs when users accumulate access rights over time without timely revocation of unneeded prior permissions.
Which process reviews and validates that user access rights remain appropriate and aligned with job responsibilities?
Answer: Access recertification (access review)
Access recertification (also called periodic access review) ensures that user permissions are still necessary and appropriate, and removes stale or excess access.
In XACML (eXtensible Access Control Markup Language), which component evaluates the policy and returns a decision?
Answer: Policy Decision Point (PDP)
The PDP evaluates access requests against applicable policies and returns Permit, Deny, NotApplicable, or Indeterminate decisions.