Join the discussion
Question 98/153
Which of the following security design patterns provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data?
Correct Answer: C
Explanation/Reference:
Explanation: Password propagation provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data. Answer: D is incorrect.
Account lockout implements a limit on the incorrect password attempts to protect an account from automated password-guessing attacks. Answer: B is incorrect. Authenticated session allows a user to access more than one access-restricted Web page without re-authenticating every page. It also integrates user authentication into the basic session model. Answer: A is incorrect. Secure assertion distributes application-specific sanity checks throughout the system.
Explanation: Password propagation provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data. Answer: D is incorrect.
Account lockout implements a limit on the incorrect password attempts to protect an account from automated password-guessing attacks. Answer: B is incorrect. Authenticated session allows a user to access more than one access-restricted Web page without re-authenticating every page. It also integrates user authentication into the basic session model. Answer: A is incorrect. Secure assertion distributes application-specific sanity checks throughout the system.
Add Comments
- Other Question (153q)
- Q1. A number of security patterns for Web applications under the DARPA contract have been deve...
- Q2. Which of the following scanning techniques helps to ensure that the standard software conf...
- Q3. Which of the following plans is designed to protect critical business processes from natur...
- Q4. Which of the following is a signature-based intrusion detection system (IDS) ?...
- Q5. Which of the following are the principle duties performed by the BIOS during POST (power-o...
- Q6. Which of the following NIST Special Publication documents provides a guideline on network ...
- Q7. Which of the following NIST Special Publication documents provides a guideline on question...
- Q8. Which of the following statements is true about residual risks?...
- Q9. According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnera...
- Q10. Which of the following are the responsibilities of the owner with regard to data in an inf...
- Q11. Which of the following are the levels of public or commercial data classification system? ...
- Q12. Which of the following security design principles supports comprehensive and simple design...
- Q13. You are the project manager for your organization. You are preparing for the quantitative ...
- Q14. Mark is the project manager of the NHQ project in StarTech Inc. The project has an asset v...
- Q15. You work as a Security Manager for Tech Perfect Inc. In the organization, Syslog is used f...
- Q16. The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the...
- Q17. Which of the following life cycle modeling activities establishes service relationships an...
- Q18. Which of the following strategies is used to minimize the effects of a disruptive event on...
- Q19. Which of the following is a chronological record of system activities to enable the recons...
- Q20. The NIST ITL Cloud Research Team defines some primary and secondary technologies as the fu...
- Q21. Which of the following statements about the availability concept of Information security m...
- Q22. Which of the following is a name, symbol, or slogan with which a product is identified?...
- Q23. You work as the Senior Project manager in Dotcoiss Inc. Your company has started a softwar...
- Q24. Which of the following steps of the LeGrand Vulnerability-Oriented Risk Management method ...
- Q25. Which of the following security controls works as the totality of protection mechanisms wi...
- Q26. DRAG DROP Auditing is used to track user accounts for file and object access, logon attemp...
- Q27. Which of the following are the types of intellectual property? Each correct answer represe...
- Q28. Which of the following is a formula, practice, process, design, instrument, pattern, or co...
- Q29. Which of the following statements about a host-based intrusion prevention system (HIPS) ar...
- Q30. The NIST ITL Cloud Research Team defines some primary and secondary technologies as the fu...
- Q31. Which of the following are included in Technical Controls? Each correct answer represents ...
- Q32. The Systems Development Life Cycle (SDLC) is the process of creating or altering the syste...
- Q33. A Web-based credit card company had collected financial and personal details of Mark befor...
- Q34. Penetration testing (also called pen testing) is the practice of testing a computer system...
- Q35. Copyright holders, content providers, and manufacturers use digital rights management (DRM...
- Q36. Which of the following are the scanning methods used in penetration testing? Each correct ...
- Q37. Which of the following phases of DITSCAP includes the activities that are necessary for th...
- Q38. John works as a professional Ethical Hacker. He has been assigned the project of testing t...
- Q39. Which of the following DoD directives defines DITSCAP as the standard C&A process for ...
- Q40. You are responsible for network and information security at a large hospital. It is a sign...
- Q41. Which of the following technologies is used by hardware manufacturers, publishers, copyrig...
- Q42. You work as a project manager for a company. The company has started a new security softwa...
- Q43. Who amongst the following makes the final accreditation decision?...
- Q44. Which of the following are the important areas addressed by a software system's security p...
- Q45. Which of the following types of attacks occurs when an attacker successfully inserts an in...
- Q46. DRAG DROP A number of security design patterns are developed for software assurance in gen...
- Q47. Which of the following documents were developed by NIST for conducting Certification &...
- Q48. Which of the following requires all general support systems and major applications to be f...
- Q49. Which of the following classification levels defines the information that, if disclosed to...
- Q50. Which of the following is a patch management utility that scans one or more computers on a...
- Q51. The Chief Information Officer (CIO), or Information Technology (IT) director, is a job tit...
- Q52. Which of the following authentication methods is used to access public areas of a Web site...
- Q53. What are the security advantages of virtualization, as described in the NIST Information S...
- Q54. Which of the following steps of the LeGrand Vulnerability-Oriented Risk Management method ...
- Q55. You have a storage media with some data and you make efforts to remove this data. After pe...
- Q56. "Enhancing the Development Life Cycle to Produce Secure Software" summarizes the tools and...
- Q57. John works as a professional Ethical Hacker. He is assigned a project to test the security...
- Q58. To help review or design security controls, they can be classified by several criteria . O...
- Q59. To help review or design security controls, they can be classified by several criteria. On...
- Q60. FIPS 199 defines the three levels of potential impact on organizations. Which of the follo...
- Q61. You are the project manager for GHY Project and are working to create a risk response for ...
- Q62. Which of the following methods offers a number of modeling practices and disciplines that ...
- Q63. Which of the following refers to a process that is used for implementing information secur...
- Q64. An assistant from the HR Department calls you to ask the Service Hours & Maintenance S...
- Q65. FITSAF stands for Federal Information Technology Security Assessment Framework. It is a me...
- Q66. In which of the following deployment models of cloud is the cloud infrastructure operated ...
- Q67. In which of the following levels of exception safety are operations succeeded with full gu...
- Q68. You work as a project manager for BlueWell Inc. You are working on a project and the manag...
- Q69. SIMULATION Fill in the blank with an appropriate phrase. is used to provide security mecha...
- Q70. The National Information Assurance Certification and Accreditation Process (NIACAP) is the...
- Q71. What component of the change management system is responsible for evaluating, testing, and...
- Q72. Which of the following elements of the BCP process emphasizes on creating the scope and th...
- Q73. What are the various benefits of a software interface according to the "Enhancing the Deve...
- Q74. What are the subordinate tasks of the Implement and Validate Assigned IA Control phase in ...
- Q75. Which of the following roles is also known as the accreditor?...
- Q76. You work as a security engineer for BlueWell Inc. You want to use some techniques and proc...
- Q77. Which of the following methods determines the principle name of the current user and retur...
- Q78. You work as a Security Manager for Tech Perfect Inc. You want to save all the data from th...
- Q79. Which of the following is generally used in packages in order to determine the package or ...
- Q80. Which of the following is a formula, practice, process, design, instrument, pattern, or co...
- Q81. Rob is the project manager of the IDLK Project for his company. This project has a budget ...
- Q82. Which of the following agencies is responsible for funding the development of many technol...
- Q83. The organization level is the Tier 1 and it addresses risks from an organizational perspec...
- Q84. Which of the following are the responsibilities of a custodian with regard to data in an i...
- Q85. DRAG DROP Drop the appropriate value to complete the formula. (Exhibit)...
- Q86. Which of the following processes identifies the threats that can impact the business conti...
- Q87. DRAG DROP Drag and drop the appropriate external constructs in front of their respective f...
- Q88. Information Security management is a process of defining the security controls in order to...
- Q89. John works as a systems engineer for BlueWell Inc. He has modified the software, and wants...
- Q90. Which of the following elements sets up a requirement to receive the constrained requests ...
- Q91. In which of the following testing methodologies do assessors use all available documentati...
- Q92. Which of the following is a set of exclusive rights granted by a state to an inventor or h...
- Q93. Security controls are safeguards or countermeasures to avoid, counteract, or minimize secu...
- Q94. In which of the following testing methods is the test engineer equipped with the knowledge...
- Q95. Which of the following are the basic characteristics of declarative security? Each correct...
- Q96. Which of the following types of obfuscation transformation increases the difficulty for a ...
- Q97. You are the project manager of the GHY project for your organization. You are about to sta...
- Q98. Which of the following security design patterns provides an alternative by requiring that ...
- Q99. Which of the following attacks causes software to fail and prevents the intended users fro...
- Q100. Which of the following security models focuses on data confidentiality and controlled acce...
- Q101. You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the...
- Q102. Which of the following terms refers to the protection of data against unauthorized access?...
- Q103. Which of the following activities are performed by the 'Do' cycle component of PDCA (plan-...
- Q104. Which of the following types of signatures is used in an Intrusion Detection System to tri...
- Q105. Which of the following authentication methods is used to access public areas of a Web site...
- Q106. Audit trail or audit log is a chronological sequence of audit records, each of which conta...
- Q107. Which of the following is designed to detect unwanted attempts at accessing, manipulating,...
- Q108. You are the project manager for a construction project. The project involves casting of a ...
- Q109. System Authorization is the risk management process. System Authorization Plan (SAP) is a ...
- Q110. Which of the following security models focuses on data confidentiality and controlled acce...
- Q111. You work as a Security Manager for Tech Perfect Inc. The company has a Windows based netwo...
- Q112. The DARPA paper defines various procedural patterns to perform secure system development p...
- Q113. Which of the following are the types of intellectual property? Each correct answer represe...
- Q114. Security is a state of well-being of information and infrastructures in which the possibil...
- Q115. A number of security patterns for Web applications under the DARPA contract have been deve...
- Q116. Which of the following rated systems of the Orange book has mandatory protection of the TC...
- Q117. The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obta...
- Q118. Which of the following elements of the BCP process emphasizes on creating the scope and th...
- Q119. Which of the following is used by attackers to record everything a person types, including...
- Q120. Which of the following sections come under the ISO/IEC 27002 standard?...
- Q121. You work as a Security Manager for Tech Perfect Inc. In the organization, Syslog is used f...
- Q122. Which of the following methods can be helpful to eliminate social engineering threat? Each...
- Q123. Audit trail or audit log is a chronological sequence of audit records, each of which conta...
- Q124. Which of the following phases of NIST SP 800-37 C&A methodology examines the residual ...
- Q125. Which of the following is the process of finding weaknesses in cryptographic algorithms an...
- Q126. What project management plan is most likely to direct the quantitative risk analysis proce...
- Q127. In which of the following deployment models of cloud is the cloud infrastructure administe...
- Q128. Part of your change management plan details what should happen in the change control syste...
- Q129. Which of the following statements about the integrity concept of information security mana...
- Q130. The Data and Analysis Center for Software (DACS) specifies three general principles for so...
- Q131. In which type of access control do user ID and password system come under?...
- Q132. Which of the following processes will you involve to perform the active analysis of the sy...
- Q133. A Web-based credit card company had collected financial and personal details of Mark befor...
- Q134. Which of the following concepts represent the three fundamental principles of information ...
- Q135. In which of the following phases of the SDLC does the software and other components of the...
- Q136. Which of the following types of attacks is targeting a Web server with multiple compromise...
- Q137. You work as a Security Manager for Tech Perfect Inc. The company has a Windows based netwo...
- Q138. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scena...
- Q139. In which of the following types of tests are the disaster recovery checklists distributed ...
- Q140. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the f...
- Q141. Which of the following governance bodies provides management, operational and technical co...
- Q142. Which of the following security controls works as the totality of protection mechanisms wi...
- Q143. According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Informat...
- Q144. You work as the senior project manager in SoftTech Inc. You are working on a software proj...
- Q145. Single Loss Expectancy (SLE) represents an organization's loss from a single threat. Which...
- Q146. The Web resource collection is a security constraint element summarized in the Java Servle...
- Q147. Which of the following is an attack with IP fragments that cannot be reassembled?...
- Q148. Which of the following statements are true about declarative security? Each correct answer...
- Q149. Which of the following security issues does the Bell-La Padula model focus on?...
- Q150. An organization monitors the hard disks of its employees' computers from time to time. Whi...
- Q151. Which of the following models manages the software development process if the developers a...
- Q152. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the f...
- Q153. Which of the following test methods has the objective to test the IT system from the viewp...
