Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Authentication & Access ControlEasy
Q1. What are the three main factors of authentication?
- A.Name, address, phone within enterprise security environments
- B.Hardware, software, firmware within enterprise security environments
- C.Username, password, email within enterprise security environments
- D.Something you know, something you have, something you are✓ Correct
Explanation
The three factors are: knowledge (something you know), possession (something you have), and inherence (something you are).
Report an error in this question
Authentication & Access ControlEasy
Q2. What is a biometric authentication method?
- A.Authenticating identity using a traditional password or passphrase
- B.Using physical characteristics like fingerprints or facial recognition to verify identity✓ Correct
- C.Using a smart card hardware token for two-factor authentication
- D.Using a numeric PIN code for verifying user identity at login
Explanation
Biometric authentication uses unique physical or behavioral characteristics for identity verification.
Report an error in this question
Authentication & Access ControlEasy
Q3. What is multi-factor authentication (MFA)?
- A.Using multiple different passwords for one account
- B.Using two or more different verification methods to confirm identity✓ Correct
- C.Displaying multiple login screens for a single service
- D.Using multiple different usernames for one account
Explanation
MFA requires two or more independent verification factors to authenticate a user.
Report an error in this question
Authentication & Access ControlEasy
Q4. What is the purpose of a username?
- A.To speed up computer processing performance speed
- B.To identify a specific user account in a system✓ Correct
- C.To create automated backup copies of user data
- D.To encrypt data using symmetric cipher algorithms
Explanation
A username serves as a unique identifier for a user account during the identification phase.
Report an error in this question
Authentication & Access ControlEasy
Q5. What is role-based access control (RBAC)?
- A.Access permissions assigned based on a user's role within the organization✓ Correct
- B.No formal access control mechanism exists in the system
- C.Everyone has the same unrestricted access to resources
- D.Access is assigned randomly without specific criteria
Explanation
RBAC assigns permissions to organizational roles rather than individual users.
Report an error in this question
Authentication & Access ControlEasy
Q6. What is a PIN (Personal Identification Number)?
- A.A numeric password used to authenticate a user's identity✓ Correct
- B.A symmetric key data encryption algorithm
- C.A network identifier assigned to connected devices
- D.A physical metal pin used for hardware components
Explanation
A PIN is a short numeric code used as a knowledge-based authentication factor.
Report an error in this question
Authentication & Access ControlEasy
Q7. What is a one-time password (OTP)?
- A.A shared password used by multiple user accounts
- B.A permanent password that never expires or changes
- C.A password valid for only one login session or transaction✓ Correct
- D.A master password that unlocks all system accounts
Explanation
An OTP is valid for only one authentication session, providing additional security.
Report an error in this question
Authentication & Access ControlEasy
Q8. What is authorization?
- A.Permanently deleting files and data from the system storage drives
- B.Determining what resources and actions an authenticated user is allowed to access✓ Correct
- C.Creating and provisioning a new user account entry in the directory
- D.Verifying and confirming who you are as a user during the login process
Explanation
Authorization determines what permissions and access rights an authenticated user has.
Report an error in this question
Authentication & Access ControlEasy
Q9. What is account lockout?
- A.Normally logging out of an active and authenticated user session
- B.A security mechanism that locks an account after too many failed login attempts✓ Correct
- C.Permanently deleting and removing a user account from the system
- D.Changing a user account password for improved security posture
Explanation
Account lockout disables an account after too many failed attempts, protecting against brute-force attacks.
Report an error in this question
Authentication & Access ControlEasy
Q10. What is single sign-on (SSO)?
- A.An authentication scheme allowing a user to log in once and access multiple systems✓ Correct
- B.A next-generation firewall for filtering network traffic flows
- C.Creating a single user account for system administration
- D.Using one password for everything without variation
Explanation
SSO allows users to authenticate once and access multiple independent systems without re-authenticating.
Report an error in this question
Authentication & Access ControlMedium
Q11. What is privilege escalation?
- A.Installing new software applications on the system
- B.Gaining elevated access rights beyond what was initially authorized✓ Correct
- C.Receiving a job promotion or advancement opportunity
- D.Creating a new user account with default permissions
Explanation
Privilege escalation occurs when a user gains higher access rights than intended.
Report an error in this question
Authentication & Access ControlMedium
Q12. What is the difference between authentication and authorization?
- A.Neither process is used in modern security frameworks
- B.Authentication verifies identity, authorization determines permissions✓ Correct
- C.Authorization always comes before the authentication phase
- D.They are functionally identical frameworks with no differences
Explanation
Authentication confirms identity through credentials, while authorization determines permitted access.
Report an error in this question
Authentication & Access ControlMedium
Q13. What is a federated identity?
- A.A physical security measure for protecting building infrastructure
- B.A fake identity created for fraudulent purposes used in enterprise computing environments
- C.A temporary identity assigned for a single session used in enterprise computing environments
- D.A system allowing users to use the same identity credentials across multiple organizations✓ Correct
Explanation
Federated identity links user identity across multiple security domains for cross-organization access.
Report an error in this question
Authentication & Access ControlMedium
Q14. What is the purpose of a RADIUS server?
- A.To provide centralized authentication, authorization, and accounting for network access✓ Correct
- B.To measure and calculate distances between network nodes and management
- C.To increase and optimize overall network throughput speed
- D.To create and deploy enterprise wireless network infrastructure
Explanation
RADIUS provides centralized AAA management for users connecting to network services.
Report an error in this question
Authentication & Access ControlMedium
Q15. What is LDAP used for in access control?
- A.A file format used for structured data storage for managing enterprise data resources
- B.A high-level language used for development within modern computing environments
- C.A software application used for enterprise computing operations
- D.A protocol for accessing distributed directory information services for centralized authentication✓ Correct
Explanation
LDAP is used to access centralized directory services that store user credentials for authentication.
Report an error in this question
Authentication & Access ControlMedium
Q16. What is attribute-based access control (ABAC)?
- A.Access control decisions based solely on user age and demographics
- B.Access control evaluating attributes of users, resources, actions, and environment✓ Correct
- C.Randomized access control without any defined criteria or policies
- D.Access control based on file system attributes exclusively without context
Explanation
ABAC evaluates rules against attributes of users, resources, actions, and environment for access decisions.
Report an error in this question
Authentication & Access ControlHard
Q17. What is Kerberos authentication protocol?
- A.A software application used for enterprise computing operations
- B.A ticket-based network authentication protocol using symmetric key cryptography and a trusted third party✓ Correct
- C.A standard web browser for accessing internet sites within modern computing environments
- D.A standard network communication protocol for data transmission
Explanation
Kerberos uses a Key Distribution Center to issue time-limited tickets for authentication without transmitting passwords.
Report an error in this question
Authentication & Access ControlMedium
Q18. What is the purpose of access control matrices?
- A.To define access rights of subjects to objects in a structured format✓ Correct
- B.To encrypt data using symmetric cipher algorithms
- C.To compress files for reducing disk storage consumption
- D.To create and format data management spreadsheets
Explanation
An access control matrix defines what operations each subject can perform on each resource.
Report an error in this question
Authentication & Access ControlHard
Q19. What is the difference between RBAC and ABAC in scalability?
- A.Neither is scalable within enterprise security environments
- B.RBAC is always more scalable regardless of the specific situation or context
- C.ABAC is more scalable for complex environments as it uses attributes rather than requiring new roles✓ Correct
- D.They scale identically with no meaningful distinction between them
Explanation
ABAC scales better in complex environments, avoiding the role explosion problem of RBAC.
Report an error in this question
Authentication & Access ControlMedium
Q20. What is the purpose of session management in authentication?
- A.To schedule tasks within enterprise computing infrastructure
- B.To securely maintain a user's authenticated state throughout their interaction✓ Correct
- C.To manage network sessions across the enterprise network infrastructure
- D.To manage computer memory within enterprise computing infrastructure
Explanation
Session management maintains authenticated state using tokens while ensuring sessions expire securely.
Report an error in this question
Authentication & Access ControlMedium
Q21. What is SAML (Security Assertion Markup Language)?
- A.A high-level language used for development within modern computing environments
- B.A software application used for enterprise computing operations
- C.An XML-based standard for exchanging authentication and authorization data between providers✓ Correct
- D.A database management system for storing structured records
Explanation
SAML allows identity providers to pass authentication credentials to service providers for SSO.
Report an error in this question
Authentication & Access ControlMedium
Q22. What is adaptive authentication?
- A.A biometric method within enterprise computing environments
- B.An approach adjusting security requirements based on risk factors like location and behavior✓ Correct
- C.A credential management mechanism for user authentication flows
- D.Fixed authentication rules within enterprise security environments
Explanation
Adaptive authentication dynamically adjusts requirements based on contextual risk factors.
Report an error in this question
Authentication & Access ControlHard
Q23. What is continuous authentication?
- A.Logging into the system repeatedly at regular intervals across computing environments
- B.A type of multi-factor authentication using OTP tokens used in enterprise computing environments
- C.Continuously verifying identity throughout a session using behavioral biometrics and contextual signals✓ Correct
- D.A session timeout feature that logs users out within the identity management system
Explanation
Continuous authentication monitors user behavior throughout a session to ensure the authenticated user is still present.
Report an error in this question
Authentication & Access ControlHard
Q24. What is the OAuth 2.0 authorization code flow?
- A.A flow where the client receives an authorization code exchanged for tokens via a back-channel✓ Correct
- B.A file transfer process within enterprise computing environments
- C.A simple password exchange within the identity management system
- D.A database query method for managing enterprise data resources
Explanation
The authorization code flow uses a secure back-channel to exchange codes for tokens, keeping tokens out of the browser.
Report an error in this question
Authentication & Access ControlHard
Q25. What is just-in-time (JIT) access provisioning?
- A.A type of SSO used across multiple services within enterprise computing environments
- B.Permanent access granted for all users regardless of the specific situation or context
- C.Fast login systems used for authentication within enterprise security environments
- D.Granting privileged access only when needed for a specific duration, then automatically revoking it✓ Correct
Explanation
JIT access grants elevated privileges only when needed and automatically revokes them afterward.
Report an error in this question
Authentication & Access ControlHard
Q26. What is the purpose of Privileged Access Management (PAM)?
- A.To create user accounts for enterprise computing environments
- B.To manage email accounts within enterprise computing infrastructure
- C.To secure, manage, and monitor privileged accounts and access to critical systems✓ Correct
- D.To design websites for enterprise computing environments and management
Explanation
PAM solutions manage and audit privileged access including credential vaulting and session recording.
Report an error in this question
Authentication & Access ControlHard
Q27. What is claim-based identity?
- A.A type of insurance policy covering liability damages used in enterprise computing environments
- B.Using assertions about a user made by a trusted identity provider for authentication and authorization✓ Correct
- C.A file management system for organizing stored documents used in enterprise computing environments
- D.Filing legal claims in a court of law or tribunal within enterprise security environments
Explanation
Claim-based identity uses assertions issued by trusted providers about user attributes for access decisions.
Report an error in this question
Authentication & Access ControlHard
Q28. What is certificate-based authentication?
- A.A training certification program for development used in enterprise computing environments
- B.Using digital certificates (X.509) to verify identity, preferred for machine-to-machine communication✓ Correct
- C.A structured file format used for data storage and exchange
- D.Using paper certificates for physical identity verification
Explanation
Certificate-based authentication uses X.509 digital certificates for identity verification in high-security environments.
Report an error in this question
Authentication & Access ControlHard
Q29. What is the FIDO2 authentication standard?
- A.A passwordless authentication standard using public-key cryptography with hardware authenticators✓ Correct
- B.A standard network communication protocol for data transmission
- C.A credential management mechanism for user authentication flows
- D.A file format used for structured data storage for managing enterprise data resources
Explanation
FIDO2 enables passwordless authentication using public-key cryptography with hardware authenticators.
Report an error in this question
Authentication & Access ControlHard
Q30. What is a pass-the-hash attack?
- A.A hashing algorithm used for data integrity within enterprise computing environments
- B.Sharing passwords openly across teams within enterprise security environments for access
- C.A credential management mechanism designed for enterprise user authentication flows
- D.An attack where captured password hashes are used directly to authenticate without knowing the password✓ Correct
Explanation
Pass-the-hash uses captured hashes directly to authenticate without cracking the actual password.
Report an error in this question