← All CAP Flashcard Decks

Authorization & Access Control Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Authorization & Access Control flashcards as text
  1. Which of the following is the PRIMARY purpose of an access control list (ACL) on a file system?

    Answer: Specifying which users or groups can perform specific operations on a resource

    An ACL is a list of permissions attached to a resource that specifies which subjects can perform which operations (read, write, execute) on it.

  2. The Biba integrity model's 'simple integrity property' prohibits a subject from:

    Answer: Reading data from a lower integrity level

    Biba's simple integrity property (no read-down) prevents subjects from reading lower-integrity data to protect the integrity of higher-integrity processes.

  3. Which authorization concept is violated when a developer has both write access to production code AND the ability to deploy it to production without review?

    Answer: Separation of duties

    Allowing one person to both write and deploy code removes the check-and-balance that separation of duties is designed to provide.

  4. In a zero trust architecture, what is the default access posture for any user or device attempting to connect to a resource?

    Answer: Denied until explicitly verified and authorized

    Zero trust assumes no implicit trust — every access request must be explicitly verified and authorized regardless of network location.

  5. Which NIST RMF step involves granting an Authority to Operate (ATO) after reviewing residual risk?

    Answer: Authorize

    The Authorize step is where the Authorizing Official (AO) reviews the security assessment package and decides whether to grant, deny, or conditionally grant an ATO.

  6. A web application verifies that an authenticated user can only access their own account records and not those of other users. This check enforces:

    Answer: Horizontal access control

    Horizontal access control restricts users at the same privilege level from accessing each other's data — failure causes insecure direct object reference (IDOR) vulnerabilities.

  7. Which of the following BEST describes the concept of 'defense in depth' as applied to access control?

    Answer: Layering multiple independent access control mechanisms so that failure of one does not compromise the system

    Defense in depth applies multiple overlapping access control layers so that bypassing or failing one control does not grant full access to a resource.