Free Practice Quiz Question List

6 Access Control Online Quiz Questions

Use this free practice quiz with 20 questions to review 6 Access Control, test your knowledge, and prepare for your next test or exam.

20 questions
01
Choose one
1 point

A user requests permission to edit a specific file. What does authorization determine?

  1. A

    A list of every resource a user has created

  2. B

    A decision to permit or deny a particular request

  3. C

    A record of when a user last signed in

  4. D

    A process for assigning job titles

02
True or false
1 point

In discretionary access control, a resource owner can grant or revoke access to that resource.

  1. A

    True

  2. B

    False

03
Written response
1 point

A company assigns permissions to job-function roles, then gives employees access through their assigned roles. Which access-control model is this? Enter the model's acronym.

04
Fill in the blank
1 point

A system grants access only when an applicable policy explicitly allows it. This practice is called .

05
Choose one
1 point

A government system assigns security labels to information and applies a central policy that users cannot override by changing file permissions. Which model best fits?

  1. A

    The resource owner decides who can access it

  2. B

    Permissions are assigned through job-function roles

  3. C

    A central policy uses classifications or labels to govern access

  4. D

    Access is decided only by the user's current location

06
Choose all
1 point

Which two practices apply the principle of least privilege? Select all that apply.

  1. A

    Give a staff member access only to the specific records needed for assigned work

  2. B

    Give every staff member administrator rights to avoid access delays

  3. C

    Provide temporary, task-specific elevation for an approved exceptional task

  4. D

    Keep all elevated permissions permanently after the task is complete

07
True or false
1 point

If a user was authorized when signing in, an application does not need to check authorization again when the user requests access to an individual record.

  1. A

    True

  2. B

    False

08
Fill in the blank
1 point

One employee prepares a payment and another approves it, so one person cannot complete the sensitive process alone. This illustrates .

09
Written response
1 point

A service account needs to process orders but not change system settings. What principle supports granting it only the access needed for that task? Enter the principle's name.

10
Choose one
1 point

A clinic permits a clinician to view a patient's record only if the clinician is assigned to that patient and is using an approved device. Which model best expresses this context-sensitive rule?

  1. A

    DAC, because resource owners always decide access based on device type

  2. B

    ABAC, because the policy can evaluate subject, resource, action, and environmental attributes

  3. C

    MAC, because the clinician can change the central policy

  4. D

    RBAC, because role assignment necessarily checks the device being used

11
Choose all
1 point

Which actions are part of sound access-control administration? Select all that apply.

  1. A

    Identify protected resources, permitted actions, and approval requirements when defining policy

  2. B

    Verify business need and obtain appropriate approval before assigning access

  3. C

    Grant broad administrator rights first and determine business need later

  4. D

    Keep records of access approvals and permission changes

12
Open ended
1 point

An organization uses job roles to grant routine permissions but wants to restrict access to sensitive data based on a request's context. Explain how it could combine two access-control models to achieve this.

13
Choose one
1 point

An administrator needs a record of which entities may access a particular file and whether each may read or edit it. What does an access-control list provide?

  1. A

    It records which entities may access a resource and which access modes they have

  2. B

    It assigns every user the same permissions across all resources

  3. C

    It records only whether a user has signed in successfully

  4. D

    It replaces the need to specify permissions for individual resources

14
Choose one
1 point

A project-file owner decides which colleagues may read or edit the file and can revoke that access later. Which access-control model best describes this arrangement?

  1. A

    Discretionary access control (DAC)

  2. B

    Mandatory access control (MAC)

  3. C

    Role-based access control (RBAC)

  4. D

    Attribute-based access control (ABAC)

15
Choose one
1 point

An organization assigns classifications to information and enforces a central policy that users cannot override by changing file permissions. Which access-control model is being used?

  1. A

    Discretionary access control (DAC)

  2. B

    Mandatory access control (MAC)

  3. C

    Role-based access control (RBAC)

  4. D

    Attribute-based access control (ABAC)

16
Choose one
1 point

A company assigns invoice-approval permissions to the “finance approver” role, then gives employees access by assigning them that role. Which model does this illustrate?

  1. A

    Discretionary access control (DAC)

  2. B

    Mandatory access control (MAC)

  3. C

    Role-based access control (RBAC)

  4. D

    Attribute-based access control (ABAC)

17
Choose one
1 point

A system permits a clinician to view a patient record only when the clinician is assigned to that patient and is using an approved device. Which access-control model most directly expresses this rule?

  1. A

    Discretionary access control (DAC)

  2. B

    Mandatory access control (MAC)

  3. C

    Role-based access control (RBAC)

  4. D

    Attribute-based access control (ABAC)

18
True or false
1 point

The principle of least privilege applies to service accounts and applications as well as ordinary users.

  1. A

    True

  2. B

    False

19
Written response
1 point

What is the name for a record that lists which entities may access a resource and which access modes they have?

20
Written response
1 point

What term describes unnecessary access accumulating over time when permissions are not adjusted as a person's duties change?