Another type of access control is lattice-based access control. In this type of control a lattice model is applied. How is this type of access control concept applied?
Correct Answer: A
In this type of control, a lattice model is applied. To apply this concept to access control, the pair of elements is the subject and object, and the subject has to have an upper bound equal or higher than the object being accessed. WIKIPEDIA has a great explanation as well: In computer security, lattice-based access control (LBAC) is a complex access control based on the interaction between any combination of objects (such as resources, computers, and applications) and subjects (such as individuals, groups or organizations). In this type of label-based mandatory access control model, a lattice is used to define the levels of security that an object may have and that a subject may have access to. The subject is only allowed to access an object if the security level of the subject is greater than or equal to that of the object. Reference(s) used for this question: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 34 and http://en.wikipedia.org/wiki/Lattice-based_access_control
Question 12
A one-way hash provides which of the following?
Correct Answer: C
Explanation/Reference: Explanation: The verification of message integrity is an important application of secure hashes. Incorrect Answers: A, D: A hash function provides Integrity, not confidentiality or authentication. B: A hash function provides Integrity, not availability. References: https://en.wikipedia.org/wiki/Cryptographic_hash_function Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 825
Question 13
The Domain Name System (DNS) is a global network of:
Correct Answer: A
The Domain Name System (DNS) is a global network of servers that provide these Domain Name Services. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 100.
Question 14
Which of the following is a responsibility of the information owner?
Correct Answer: A
Question 15
Which one of the following is a KEY responsibility for the "Custodian of Data"?
Correct Answer: B
Custodian - Preserves the information's CIA (chart) -Ronald Krutz The CISSP PREP Guide (gold edition) pg 15