Authentication
Access Control
Account Management
Identity Management
Mixed Challenge
100

Sarah logs into her laptop using only a password. Which authentication factor is she using?

Something you know

100

A user can install software only after Windows asks for administrator approval. Which feature is responsible for this?

User Account Control (UAC).

100

A new employee joins a company and receives a username, password, laptop, and permissions. What process is this?

User account provisioning.

100

A user signs in once and can access email, HR, and payroll systems without logging in again. What technology is being used?

Single Sign-On (SSO).

100

A login code is sent to a user's phone by SMS after entering a password. What type of authentication token is this?

Soft authentication token.

200

A company requires employees to enter a password and then approve a notification on their phone before logging in. What security method is being used?

Multi-Factor Authentication (MFA).

200

The owner of a file decides who can access it. Which access control model is being used?

Discretionary Access Control (DAC).

200

An employee resigns, and the IT department immediately disables their account. What process is this called?

Deprovisioning.

200

A university allows students to use the same account to access both the university portal and Microsoft 365. What identity concept makes this possible?

Federation

200

An employee inserts a smart card into their computer to prove their identity. What type of authentication token is being used?

Hard authentication token

300

A company wants employees to create long, unique passwords for every website without having to remember them all. What tool should they use?

A password manager.

300

A military system allows access based on security clearance instead of the file owner's decision. Which access control model is this?

Mandatory Access Control (MAC).

300

An administrator gives users only the permissions needed to perform their jobs. Which security principle is being followed?

The Principle of Least Privilege.

300

 An application asks another trusted service to verify a user's identity instead of storing usernames and passwords itself. What type of provider performs this verification?

Identity Provider (IdP).

300

A website allows you to log in using your Google account instead of creating a new username and password. Which authorization framework is commonly used?

OAuth.

400

John unlocks his phone using his fingerprint instead of typing a password. Which authentication factor is being used?

Biometric authentication (something you are).

400

All accountants automatically receive the same permissions because they belong to the "Accounting" role. Which model is being used?

Role-Based Access Control (RBAC).

400

A company notices that an employee has accumulated unnecessary permissions after several promotions. What is this problem called?

Authorization creep.

400

An organization's directory stores users, groups, computers, and permissions in one central database. Which service is this?

Directory Services (LDAP/Directory Service).

400

During biometric testing, the system incorrectly allows an unauthorized person to log in. What is this error called?

False Acceptance Rate (FAR).

500

A company removes passwords completely. Employees authenticate using a security key and fingerprint. What authentication method is this?

Passwordless authentication.

500

A hospital grants access based on a doctor's role, current location, and time of day. Which access control model is being used?

Attribute-Based Access Control (ABAC).

500

An administrator receives elevated privileges for only one hour to complete maintenance before those privileges are automatically removed. What security practice is this?

Temporary elevation (Zero Standing Privileges).

500

A company wants different websites to trust a user's login without creating separate accounts for each site. Which open standard is commonly used?

Security Assertion Markup Language (SAML).

500

An employee logs in from South Africa and five minutes later appears to log in from Japan. Which account restriction detects this suspicious activity?

Impossible travel time (risky login).