GCC Class 2 Lesson 2 Quiz

  1. What principle of internal security limits users or groups to only the objects and resources they require to perform their duties?

    C. Principle of least privilege.
  2. The ACL statement "access-list 10 deny any" is an example of what type of access control policy?

    B. Implicit deny.
  3. What type of access control policy limits requesters to only the privileges and permissions associated with the performance of their
    job function?
    A. Role-based access control.
    B. Mandatory access control.
    C. Rules-based access control.
    D. Discretionary access control.
    A. Role-based access control.
  4. What internal control principle is intended to prevent theft and misappropriation, and limits access to secured objects?

    A. Separation of duties.
  5. What international standard denes a security specification for operating systems and access control?

    A. Common Criteria.
