Authorization & Access Control Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Authorization & Access Control flashcards as text
Which of the following is the PRIMARY purpose of an access control list (ACL) on a file system?
Answer: Specifying which users or groups can perform specific operations on a resource
An ACL is a list of permissions attached to a resource that specifies which subjects can perform which operations (read, write, execute) on it.
The Biba integrity model's 'simple integrity property' prohibits a subject from:
Answer: Reading data from a lower integrity level
Biba's simple integrity property (no read-down) prevents subjects from reading lower-integrity data to protect the integrity of higher-integrity processes.
Which authorization concept is violated when a developer has both write access to production code AND the ability to deploy it to production without review?
Answer: Separation of duties
Allowing one person to both write and deploy code removes the check-and-balance that separation of duties is designed to provide.
In a zero trust architecture, what is the default access posture for any user or device attempting to connect to a resource?
Answer: Denied until explicitly verified and authorized
Zero trust assumes no implicit trust — every access request must be explicitly verified and authorized regardless of network location.
Which NIST RMF step involves granting an Authority to Operate (ATO) after reviewing residual risk?
Answer: Authorize
The Authorize step is where the Authorizing Official (AO) reviews the security assessment package and decides whether to grant, deny, or conditionally grant an ATO.
A web application verifies that an authenticated user can only access their own account records and not those of other users. This check enforces:
Answer: Horizontal access control
Horizontal access control restricts users at the same privilege level from accessing each other's data — failure causes insecure direct object reference (IDOR) vulnerabilities.
Which of the following BEST describes the concept of 'defense in depth' as applied to access control?
Answer: Layering multiple independent access control mechanisms so that failure of one does not compromise the system
Defense in depth applies multiple overlapping access control layers so that bypassing or failing one control does not grant full access to a resource.