Unit2 - Subjective Questions

INT242 • Practice Questions with Detailed Answers

1

Distinguish between Authentication and Authorization with examples.

2

Explain the Three Factors of Authentication (MFA) and provide an example for each.

3

Describe the Identity Management (IdM) lifecycle.

4

Compare Discretionary Access Control (DAC), Mandatory Access Control (MAC), and Role-Based Access Control (RBAC).

5

What are Biometric False Acceptance Rate (FAR) and False Rejection Rate (FRR)? How are they related?

6

Explain the concept of Single Sign-On (SSO) and its benefits and drawbacks.

7

Define Federated Identity Management.

8

Explain the architecture and purpose of a DMZ (Demilitarized Zone).

9

What is Defense in Depth? Explain with layers.

10

Differentiate between Packet Filtering, Stateful Inspection, and Proxy Firewalls.

11

Compare IDS (Intrusion Detection System) and IPS (Intrusion Prevention System).

12

Explain IPsec and its two main modes of operation.

13

What are VLANs and how do they contribute to network security?

14

Describe the Zero Trust Security Model.

15

Distinguish between Remote Access VPN and Site-to-Site VPN.

16

Explain the SSL/TLS Handshake process.

17

What is a Web Application Firewall (WAF) and how does it differ from a standard network firewall?

18

Explain the purpose of Network Access Control (NAC).

19

Compare SSH and Telnet.

20

Design a Secure Network Architecture for a web application hosting sensitive database records. Detail the placement of components.