6 Authentication And Access Control

Information Security · Unit 6

Authentication and Access Control

Exam-focused notes for Authentication and Access Control (Information Security, BIT303): what the TU syllabus asks and how it has actually been tested, with 13 solved past questions from this unit.

What this unit covers

  • Authentication systems and components
  • Challenge-response authentication
  • Password-based authentication
  • Biometric authentication
  • Two-factor authentication
  • Dictionary attacks and authentication issues
  • Access control principles and models
  • Role-based access control
  • Attribute-based access control
  • Subjects, objects and access rights

Two-factor authentication

20825 marks

Why do we need two factor authentication? Discuss about security issues for user authentication. [5]

Single-factor authentication (typically a password) has several weaknesses that make it insufficient for secure systems. Two-factor authentication addresses these by requiring two independent forms of verification before granting access. Factor Type Example...

Full solved answer →
20805 marks

Discuss about two factor authentication with an example. [5]

Two-Factor Authentication (2FA) is a security mechanism that requires a user to provide two distinct forms of verification from two different categories before granting access to a system or account. It adds an extra layer of security beyond just a username...

Full solved answer →
20795 marks

Write Short Notes on: a. Phishing Attack b. Two Factor Authentication [5]

Definition: A phishing attack is a type of social engineering attack in which an attacker disguises themselves as a trustworthy entity to trick users into revealing sensitive information such as usernames, passwords, credit card numbers, or other confidenti...

Full solved answer →

Role-based access control

20825 marks

Differentiate between role based and attribute based access controls. [5]

Note: The reference notes did not contain this topic directly. The following answer is based on standard, correct information from access control theory as taught in security and operating systems courses. --- RBAC grants or restricts access to resources ba...

Full solved answer →

Subjects, objects and access rights

20825 marks

What do you mean by subjects, objects and access rights? Discuss about ethical issues in cyber security. [2.5+2.5]

--- (a) Subjects, Objects, and Access Rights A subject is an active entity that requests access to resources or objects in a system. Subjects are typically users, processes, or programs that initiate actions. Examples: - A logged-in user requesting a file -...

Full solved answer →
208110 marks

Define subjects, objects and access rights in access control with suitable examples. How role based access control is different from attribute based access control?[10]

Note: No specific curriculum notes were found for this topic. The following answer is based on standard, correct Computer Science / Information Security principles as taught in BSc CSIT Operating Systems and Information Security courses. --- Access control ...

Full solved answer →
010 marks

Consider a system having users U1, U2, U3 & files F1, F2 and F3 as F4. User U1 can read and write files F2 and F3. User U2 can read all the files but can perform write operation on F2. The user U3 can perform read operation on F3 and append on file F4. Now prepare access control matrix, access control list and capability list.[10]

Subjects (Users): U1, U2, U3 Objects (Files): F1, F2, F3, F4 Stated permissions: - U1: read and write on F2 and F3 - U2: read all files (F1, F2, F3, F4); write on F2 - U3: read on F3; append on F4 All permissions fully specified. Nothing missing. --- Rows =...

Full solved answer →

Dictionary attacks and authentication issues

20815 marks

How online and offline dictionary attacks are done in password based authentication systems? [5]

Dictionary attacks exploit the fact that users tend to choose weak, predictable passwords. An attacker uses a pre-compiled list of likely passwords (a "dictionary") and systematically tries each one. --- - The attacker directly interacts with the live authe...

Full solved answer →

Access control principles and models

20805 marks

Explain the different types of access control principles. [5]

Note: The reference notes did not contain this topic directly. The following answer is based on standard Information Security / Operating Systems curriculum as taught in BSc CSIT programs. --- Access control is a security mechanism that regulates who can ac...

Full solved answer →

Authentication systems and components

20805 marks

List some issues for user authentication. What is trust framework? [5]

--- User authentication faces several practical and security-related challenges: 1. Password Management Problems - Users tend to choose weak, easily guessable passwords - Password reuse across multiple systems increases vulnerability - Forgotten passwords l...

Full solved answer →

Attribute-based access control

20795 marks

What is access control? Explain attribute based access control with example. [5]

--- Access control is a security mechanism that regulates who or what can view, use, or perform operations on resources in a computing environment. It ensures that only authorized users can access specific resources and perform permitted actions. Access con...

Full solved answer →

Biometric authentication

20795 marks

Define authentication. How Biometric information can be used for authentication? [5]

Authentication is the process of verifying the identity of a user, system, or entity attempting to gain access to a resource. It is the mechanism by which a system confirms that someone is who they claim to be, typically before granting access to protected ...

Full solved answer →

Challenge-response authentication

05 marks

Define authentication system with its components. How challenge-response system can be used as an authentication system? [5]

--- An authentication system is a security mechanism that verifies the identity of a user, process, or device before granting access to a system or resource. It ensures that the entity claiming an identity is genuinely who or what it claims to be. --- An au...

Full solved answer →