Information Security · Unit 6
Authentication and Access Control
Exam-focused notes for Authentication and Access Control (Information Security, BIT303): what the TU syllabus asks and how it has actually been tested, with 13 solved past questions from this unit.
What this unit covers
- Authentication systems and components
- Challenge-response authentication
- Password-based authentication
- Biometric authentication
- Two-factor authentication
- Dictionary attacks and authentication issues
- Access control principles and models
- Role-based access control
- Attribute-based access control
- Subjects, objects and access rights
Two-factor authentication
Why do we need two factor authentication? Discuss about security issues for user authentication. [5]
Single-factor authentication (typically a password) has several weaknesses that make it insufficient for secure systems. Two-factor authentication addresses these by requiring two independent forms of verification before granting access. Factor Type Example...
Full solved answer →Discuss about two factor authentication with an example. [5]
Two-Factor Authentication (2FA) is a security mechanism that requires a user to provide two distinct forms of verification from two different categories before granting access to a system or account. It adds an extra layer of security beyond just a username...
Full solved answer →Write Short Notes on: a. Phishing Attack b. Two Factor Authentication [5]
Definition: A phishing attack is a type of social engineering attack in which an attacker disguises themselves as a trustworthy entity to trick users into revealing sensitive information such as usernames, passwords, credit card numbers, or other confidenti...
Full solved answer →Role-based access control
Differentiate between role based and attribute based access controls. [5]
Note: The reference notes did not contain this topic directly. The following answer is based on standard, correct information from access control theory as taught in security and operating systems courses. --- RBAC grants or restricts access to resources ba...
Full solved answer →Subjects, objects and access rights
What do you mean by subjects, objects and access rights? Discuss about ethical issues in cyber security. [2.5+2.5]
--- (a) Subjects, Objects, and Access Rights A subject is an active entity that requests access to resources or objects in a system. Subjects are typically users, processes, or programs that initiate actions. Examples: - A logged-in user requesting a file -...
Full solved answer →Define subjects, objects and access rights in access control with suitable examples. How role based access control is different from attribute based access control?[10]
Note: No specific curriculum notes were found for this topic. The following answer is based on standard, correct Computer Science / Information Security principles as taught in BSc CSIT Operating Systems and Information Security courses. --- Access control ...
Full solved answer →Consider a system having users U1, U2, U3 & files F1, F2 and F3 as F4. User U1 can read and write files F2 and F3. User U2 can read all the files but can perform write operation on F2. The user U3 can perform read operation on F3 and append on file F4. Now prepare access control matrix, access control list and capability list.[10]
Subjects (Users): U1, U2, U3 Objects (Files): F1, F2, F3, F4 Stated permissions: - U1: read and write on F2 and F3 - U2: read all files (F1, F2, F3, F4); write on F2 - U3: read on F3; append on F4 All permissions fully specified. Nothing missing. --- Rows =...
Full solved answer →Dictionary attacks and authentication issues
How online and offline dictionary attacks are done in password based authentication systems? [5]
Dictionary attacks exploit the fact that users tend to choose weak, predictable passwords. An attacker uses a pre-compiled list of likely passwords (a "dictionary") and systematically tries each one. --- - The attacker directly interacts with the live authe...
Full solved answer →Access control principles and models
Explain the different types of access control principles. [5]
Note: The reference notes did not contain this topic directly. The following answer is based on standard Information Security / Operating Systems curriculum as taught in BSc CSIT programs. --- Access control is a security mechanism that regulates who can ac...
Full solved answer →Authentication systems and components
List some issues for user authentication. What is trust framework? [5]
--- User authentication faces several practical and security-related challenges: 1. Password Management Problems - Users tend to choose weak, easily guessable passwords - Password reuse across multiple systems increases vulnerability - Forgotten passwords l...
Full solved answer →Attribute-based access control
What is access control? Explain attribute based access control with example. [5]
--- Access control is a security mechanism that regulates who or what can view, use, or perform operations on resources in a computing environment. It ensures that only authorized users can access specific resources and perform permitted actions. Access con...
Full solved answer →Biometric authentication
Define authentication. How Biometric information can be used for authentication? [5]
Authentication is the process of verifying the identity of a user, system, or entity attempting to gain access to a resource. It is the mechanism by which a system confirms that someone is who they claim to be, typically before granting access to protected ...
Full solved answer →Challenge-response authentication
Define authentication system with its components. How challenge-response system can be used as an authentication system? [5]
--- An authentication system is a security mechanism that verifies the identity of a user, process, or device before granting access to a system or resource. It ensures that the entity claiming an identity is genuinely who or what it claims to be. --- An au...
Full solved answer →Make Unit 6 stick
Practice BIT303 with flashcards & quizzes