Apply Your Knowledge

Exercises

1.1. Rule-Based or Role-Based: Which Is It?

Examine the access control system of a Windows NT or Windows 2000 system. Determine whether it is role-based or rule-based, and explain why.

Estimated Time: 20 minutes

  1. Examine the default user groups on the system. What groups exist? Do they have specific rights or access that is allowed on the system?

  2. Determine whether additional groups can be created. Who can create these groups? Can rights or access be granted to these groups?

  3. Determine whether individual user accounts can be given rights and access on the system.

  4. Based on your study, is this a rule-based or role-based system of access control? Why?

Answers to the exercise:
  1. Multiple user groups exist, depending on whether ...

Get CISSP Training Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.