CIA TRIAD
AAA
ACCESS CONTROL
THREATS & RISKS
CYBER VOCAB
100

Keeping information secret from unauthorized people

Confidentiality

100

The process of proving that you are who you claim to be

Authentication

100

Permissions are assigned based on a persons job or hierarchy.

RBAC

100

Anything that has value to an organization and needs protection.

Asset

100

Using 2 or more different methods to verify someones identity.

MFA (Multi-factor Authentication)

200

Making sure information has not been improperly changed

Integrity

200

This determines what an authenticated user is allowed to access or do.

Authorization

200

The owner of a file decides who can access it

DAC

200

A weakness that could potentially be exploited.

Vulnerability

200

A security requirement where users must provide two or more authentication factors before receiving access.

MFA 

300

Making sure systems and data can be accessed when needed

Availability

300
This records and tracks a user's activity on a system.

Accounting

300

Access is controlled using classifications or labels rather than the owner's choice.

MAC

300

Something capable of causing harm to a system or organization.

Threat

300

A security model where the creator or owner of a resource decides who gets access.

DAC (Discretionary Access Control)

400

A hacker changes students' grades without permission. Which part of the CIA Triad was violated?

Integrity

400

Joshua enters his username, password, and verification code before logging in. What security concept is being used?

MFA / 2FA

400
WHSAT gives all teachers access to the gradebook because all of our accounts are listed in the "Teacher" group. Which access control model is described?

RBAC

400

Brooklyn Latin has a school server with outdated software. The outdated software itself would be considered a ..... 

Vulnerability

400

A security model that uses centrally controlled classifications or security labels to determine access.

MAC (Mandatory Access Control)

500

A DDoS attack takes the school's website offline for six hours. Which part of the CIA Triad is primarily affected?

Availability

500

Mateo successfully logs into the school network but cannot open the teachers-only folder. Authentication succeeded but this part of AAA prevented access.

Authorization

500

A classified government document is labeled "Top Secret" and users cannot change who is allowed to access it.

MAC

500

A laptop contains student records, has an unpatched vulnerability, and a hacker attempts to exploit it. Identify the asset and the threat.

Asset: Laptop / Student Records

Threat: Hacker

500

Name all part of AAA in ORDER.

Authentication

Authorization

Accounting