Deck 3: User Authentication
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/45
Play
Full screen (f)
Deck 3: User Authentication
1
T F 4.Many users choose a password that is too short or too easy to guess.
True
2
User authentication is a procedure that allows communicating parties to
verify that the contents of a received message have not been altered and that the source is authentic.
verify that the contents of a received message have not been altered and that the source is authentic.
False
3
Keylogging is a form of host attack.
False
4
A good technique for choosing a password is to use the first letter of
each word of a phrase.
each word of a phrase.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
5
Identifiers should be assigned carefully because authenticated
identities are the basis for other security services.
identities are the basis for other security services.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
6
An individual's signature is not unique enough to use in biometric
applications.
applications.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
7
Enrollment creates an association between a user and the user's
biometric characteristics.
biometric characteristics.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
8
A smart card contains an entire microprocessor.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
9
Presenting or generating authentication information that corroborates the binding between the entity and the identifier is the ___________.
A)identification step
B)authentication step
C)verification step
D)corroboration step
A)identification step
B)authentication step
C)verification step
D)corroboration step
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
10
__________ defines user authentication as "the process of verifying an identity claimed by or for a system entity".
A)RFC 4949
B)RFC 2493
C)RFC 2298
D)RFC 2328
A)RFC 4949
B)RFC 2493
C)RFC 2298
D)RFC 2328
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
11
User authentication is the fundamental building block and the primary
line of defense.
line of defense.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
12
Identification is the means of establishing the validity of a claimed
identity provided by a user.
identity provided by a user.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
13
Depending on the application,user authentication on a biometric
system involves either verification or identification.
system involves either verification or identification.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
14
Memory cards store and process data.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
15
Recognition by fingerprint,retina,and face are examples of __________.
A)face recognition
B)static biometrics
C)dynamic biometrics
D)token authentication
A)face recognition
B)static biometrics
C)dynamic biometrics
D)token authentication
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
16
In a biometric scheme some physical characteristic of the individual is
mapped into a digital representation.
mapped into a digital representation.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
17
A __________ is a password guessing program.
A)password hash
B)password biometric
C)password cracker
D)password salt
A)password hash
B)password biometric
C)password cracker
D)password salt
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
18
The __________ strategy is when users are told the importance of using hard to guess passwords and provided with guidelines for selecting strong passwords.
A)reactive password checking
B)computer-generated password
C)proactive password checking
D)user education
A)reactive password checking
B)computer-generated password
C)proactive password checking
D)user education
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
19
Depending on the details of the overall authentication
system,the registration authority issues some sort of electronic credential to the subscriber.
system,the registration authority issues some sort of electronic credential to the subscriber.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
20
User authentication is the basis for most types of access control and for
user accountability.
user accountability.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
21
The most common means of human-to-human identification are __________.
A)facial characteristics
B)retinal patterns
C)signatures
D)fingerprints
A)facial characteristics
B)retinal patterns
C)signatures
D)fingerprints
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
22
__________ systems identify features of the hand,including shape,and lengths and widths of fingers.
A)Signature
B)Fingerprint
C)Hand geometry
D)Palm print
A)Signature
B)Fingerprint
C)Hand geometry
D)Palm print
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
23
__________ allows an issuer to access regional and national networks that connect point of sale devices and bank teller machines worldwide.
A)EFT
B)BTM
C)POS
D)ATF
A)EFT
B)BTM
C)POS
D)ATF
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
24
A host generated random number is often called a __________.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
25
A __________ is directed at the user file at the host where passwords,token passcodes,or biometric templates are stored.
A)eavesdropping attack
B)client attack
C)denial-of-service attack
D)host attack
A)eavesdropping attack
B)client attack
C)denial-of-service attack
D)host attack
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
26
To counter threats to remote user authentication,systems generally rely on some form of ___________ protocol.
A)eavesdropping
B)challenge-response
C)Trojan horse
D)denial-of-service
A)eavesdropping
B)challenge-response
C)Trojan horse
D)denial-of-service
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
27
The __________ is the pattern formed by veins beneath the retinal surface.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
28
The technique for developing an effective and efficient proactive password checker based on rejecting words on a list is based on the use of a __________ filter.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
29
A __________ strategy is one in which the system periodically runs its own password cracker to find guessable passwords.
A)user education
B)reactive password checking
C)proactive password checking
D)computer-generated password
A)user education
B)reactive password checking
C)proactive password checking
D)computer-generated password
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
30
A __________ is a separate file from the user IDs where hashed passwords are kept.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
31
Authentication protocols used with smart tokens can be classified into three categories: static,dynamic password generator,and ___________.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
32
A __________ authentication system attempts to authenticate an individual based on his or her unique physical characteristics.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
33
An institution that issues debit cards to cardholders and is responsible for the cardholder's account and authorizing transactions is the _________.
A)cardholder
B)issuer
C)auditor
D)processor
A)cardholder
B)issuer
C)auditor
D)processor
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
34
A __________ is when an adversary attempts to achieve user authentication without access to the remote host or to the intervening communications path.
A)client attack
B)host attack
C)eavesdropping attack
D)Trojan horse attack
A)client attack
B)host attack
C)eavesdropping attack
D)Trojan horse attack
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
35
A __________ attack involves an adversary repeating a previously captured user response.
A)client
B)Trojan horse
C)replay
D)eavesdropping
A)client
B)Trojan horse
C)replay
D)eavesdropping
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
36
Each individual who is to be included in the database of authorized users must first be __________ in the system.
A)verified
B)identified
C)authenticated
D)enrolled
A)verified
B)identified
C)authenticated
D)enrolled
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
37
With the __________ policy a user is allowed to select their own password,but the system checks to see if the password is allowable.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
38
Objects that a user possesses for the purpose of user authentication are called ______
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
39
An authentication process consists of the _________ step and the verification step.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
40
Voice pattern,handwriting characteristics,and typing rhythm are examples of __________ biometrics.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
41
A __________ is an individual to whom a debit card is issued.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
42
A __________ attack attempts to disable a user authentication service by flooding the service with numerous authentication attempts.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
43
In a __________ attack,an application or physical device masquerades as an authentic application or device for the purpose of capturing a user password,passcode,or biometric.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
44
The __________ step is presenting or generating authentication information that corroborates the binding between the entity and the identifier.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
45
__________,in the context of passwords,refers to an adversary's attempt to learn the password by observing the user,finding a written copy of the password,or some similar attack that involves the physical proximity of user and adversary.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck