1
00:00:06,690 --> 00:00:08,280
- Welcome to lesson 19,

2
00:00:08,280 --> 00:00:10,170
Deep Dive Quiz.

3
00:00:10,170 --> 00:00:12,510
19 was all about, given the scenario,

4
00:00:12,510 --> 00:00:16,200
implement and maintain
identity and access management.

5
00:00:16,200 --> 00:00:17,820
Now in lesson 19 one,

6
00:00:17,820 --> 00:00:20,670
we talked about identity
and access management.

7
00:00:20,670 --> 00:00:21,840
In 19 two,

8
00:00:21,840 --> 00:00:24,870
we looked at federated
identity or portable identity,

9
00:00:24,870 --> 00:00:26,910
including SAML and OAuth.

10
00:00:26,910 --> 00:00:29,370
In 19 three, we looked at authentication,

11
00:00:29,370 --> 00:00:33,330
various factors and, ways
to implement authentication.

12
00:00:33,330 --> 00:00:37,170
In 19 four, we dove right into biometrics.

13
00:00:37,170 --> 00:00:40,980
In 19 five, we looked at access
control and authentication.

14
00:00:40,980 --> 00:00:43,440
And lastly, in 19 six,

15
00:00:43,440 --> 00:00:45,870
we really talked about
the all important concept

16
00:00:45,870 --> 00:00:48,360
of privilege access management.

17
00:00:48,360 --> 00:00:51,300
So now we're gonna do
10 questions together.

18
00:00:51,300 --> 00:00:52,500
Are you ready for this quiz?

19
00:00:52,500 --> 00:00:54,180
Make sure that you have a pen or pencil

20
00:00:54,180 --> 00:00:55,350
and a piece of paper.

21
00:00:55,350 --> 00:00:58,050
Put me on pause, absolutely
as often as necessary,

22
00:00:58,050 --> 00:01:00,810
so that you can be
answering these questions.

23
00:01:00,810 --> 00:01:01,983
So let's get started.

24
00:01:04,290 --> 00:01:06,180
Our first question is
to match the following

25
00:01:06,180 --> 00:01:09,810
access control concepts and descriptions.

26
00:01:09,810 --> 00:01:10,710
I'm gonna bring this up

27
00:01:10,710 --> 00:01:13,110
so you can see it a little bit better.

28
00:01:13,110 --> 00:01:16,200
So on the left hand side, we
have rights, need to know,

29
00:01:16,200 --> 00:01:19,050
dual control and separation of duties.

30
00:01:19,050 --> 00:01:20,040
On the right hand side,

31
00:01:20,040 --> 00:01:23,430
we have a demonstrated
reason for requiring access,

32
00:01:23,430 --> 00:01:25,680
entitlements granted to users,

33
00:01:25,680 --> 00:01:29,640
requiring more than one subject
to complete a specific task,

34
00:01:29,640 --> 00:01:32,580
or breaking a task into separate processes

35
00:01:32,580 --> 00:01:35,673
so that they're assigned
to different subjects.

36
00:01:37,200 --> 00:01:38,040
See if we can see that.

37
00:01:38,040 --> 00:01:38,940
I dunno if there's a little bit more.

38
00:01:38,940 --> 00:01:39,773
There we go.

39
00:01:39,773 --> 00:01:41,223
Assigned to different subjects.

40
00:01:42,840 --> 00:01:45,090
So why don't we start right up
here on the right hand side.

41
00:01:45,090 --> 00:01:47,940
Demonstrated reason for requiring access.

42
00:01:47,940 --> 00:01:49,320
So, put me on pause if you want to

43
00:01:49,320 --> 00:01:51,020
before I start giving you answers.

44
00:01:51,900 --> 00:01:55,590
All right, demonstrated
reason for requiring access.

45
00:01:55,590 --> 00:01:57,300
That is gonna be,

46
00:01:57,300 --> 00:01:58,323
our need to know.

47
00:02:00,630 --> 00:02:01,470
Back up at the top,

48
00:02:01,470 --> 00:02:03,600
entitlements granted to users.

49
00:02:03,600 --> 00:02:05,580
Those are things like change system time,

50
00:02:05,580 --> 00:02:08,370
or create a user, or install software.

51
00:02:08,370 --> 00:02:10,173
That's gonna be our rights.

52
00:02:11,460 --> 00:02:13,620
All right, requiring more than one subject

53
00:02:13,620 --> 00:02:15,960
to complete a specific task,

54
00:02:15,960 --> 00:02:18,870
or, breaking a task
into separate processes

55
00:02:18,870 --> 00:02:21,150
that are assigned to different subjects.

56
00:02:21,150 --> 00:02:22,710
And we've got dual control,

57
00:02:22,710 --> 00:02:24,213
and separation of duties.

58
00:02:25,470 --> 00:02:27,390
What do you wanna choose?

59
00:02:27,390 --> 00:02:28,830
Well, requiring more than one subject

60
00:02:28,830 --> 00:02:30,330
to complete a specific task.

61
00:02:30,330 --> 00:02:31,860
I'm going with dual control.

62
00:02:31,860 --> 00:02:34,170
And breaking a task
into separate processes

63
00:02:34,170 --> 00:02:36,510
assigned to different subjects,

64
00:02:36,510 --> 00:02:38,580
I'm gonna go with separation of duties.

65
00:02:38,580 --> 00:02:41,640
So rights, entitlements
granted to our users,

66
00:02:41,640 --> 00:02:44,820
need to know, demonstrated
reason for requiring access,

67
00:02:44,820 --> 00:02:46,980
dual control, requiring
more than one subject

68
00:02:46,980 --> 00:02:48,750
to complete a specific task,

69
00:02:48,750 --> 00:02:51,570
And separation of duties,
breaking a task into

70
00:02:51,570 --> 00:02:54,750
separate processes that are
assigned to different subjects.

71
00:02:54,750 --> 00:02:56,010
Do you agree?

72
00:02:56,010 --> 00:02:57,063
Let's check it out.

73
00:02:58,200 --> 00:02:59,730
And we are correct.

74
00:02:59,730 --> 00:03:01,230
Okay, let's move on.

75
00:03:01,230 --> 00:03:03,870
Sue Smith is an excellent long-term

76
00:03:03,870 --> 00:03:07,410
management level employee who
has held numerous positions

77
00:03:07,410 --> 00:03:09,030
in the company.

78
00:03:09,030 --> 00:03:11,370
Based on this information alone,

79
00:03:11,370 --> 00:03:14,280
what concern might an auditor have?

80
00:03:14,280 --> 00:03:17,610
Authorization creep,
privileged management,

81
00:03:17,610 --> 00:03:21,060
need to know or unauthorized access?

82
00:03:21,060 --> 00:03:23,880
So they're a long-term
management level employee.

83
00:03:23,880 --> 00:03:24,990
It doesn't look like they're in IT

84
00:03:24,990 --> 00:03:26,550
they're a management level employee,

85
00:03:26,550 --> 00:03:29,700
and they've had numerous
positions in the company.

86
00:03:29,700 --> 00:03:32,730
Right, so over time, they've
changed their positions a lot.

87
00:03:32,730 --> 00:03:35,220
Based on just that piece of information,

88
00:03:35,220 --> 00:03:37,770
what concern might an auditor have?

89
00:03:37,770 --> 00:03:41,130
Authorization creep,
privileged management,

90
00:03:41,130 --> 00:03:44,820
need to know, or unauthorized access?

91
00:03:44,820 --> 00:03:46,120
What are you gonna choose?

92
00:03:48,450 --> 00:03:51,120
Well, there is no indication, right,

93
00:03:51,120 --> 00:03:53,250
that, she has standing privilege, right?

94
00:03:53,250 --> 00:03:55,290
There's nothing that says
she's an IT administrator

95
00:03:55,290 --> 00:03:57,360
or she's a custodian.

96
00:03:57,360 --> 00:03:59,370
Need to know, doesn't really,

97
00:03:59,370 --> 00:04:01,520
isn't really relevant here.

98
00:04:01,520 --> 00:04:05,190
There's no suggestion that
she's done anything wrong,

99
00:04:05,190 --> 00:04:07,800
that there's any unauthorized access.

100
00:04:07,800 --> 00:04:10,710
But because she's been
here for a long time,

101
00:04:10,710 --> 00:04:12,960
and she's had numerous positions,

102
00:04:12,960 --> 00:04:15,210
absolutely as an auditor,

103
00:04:15,210 --> 00:04:18,540
I would be concerned
with authorization creep.

104
00:04:18,540 --> 00:04:20,910
As she's moved from one
position to another,

105
00:04:20,910 --> 00:04:21,743
I wanna make sure that as

106
00:04:21,743 --> 00:04:23,670
she's given new rights and permissions,

107
00:04:23,670 --> 00:04:27,180
that her old rights and
permissions have been recovered.

108
00:04:27,180 --> 00:04:28,440
Do you agree?

109
00:04:28,440 --> 00:04:30,000
All right, let's check.

110
00:04:30,000 --> 00:04:31,143
And that is correct.

111
00:04:34,050 --> 00:04:35,580
Question three.

112
00:04:35,580 --> 00:04:38,850
On an annual basis, management
is asked to validate

113
00:04:38,850 --> 00:04:42,600
that user rights and permission
assignments are correct.

114
00:04:42,600 --> 00:04:44,580
This process is known as,

115
00:04:44,580 --> 00:04:48,360
access attestation, accreditation,

116
00:04:48,360 --> 00:04:52,110
role management, or change management?

117
00:04:52,110 --> 00:04:53,700
So annually, in this case,

118
00:04:53,700 --> 00:04:55,050
we're asking management to say,

119
00:04:55,050 --> 00:04:57,056
yep those user rights and permissions

120
00:04:57,056 --> 00:04:58,830
assignments are correct.

121
00:04:58,830 --> 00:05:00,810
We're probably saying, are they also

122
00:05:00,810 --> 00:05:03,390
in the right groups,
or in the right roles?

123
00:05:03,390 --> 00:05:06,120
Access attestation, accreditation,

124
00:05:06,120 --> 00:05:08,310
role management, or change management?

125
00:05:08,310 --> 00:05:09,910
What's the term we're gonna use?

126
00:05:11,790 --> 00:05:14,580
Well, I like, access attestation.

127
00:05:14,580 --> 00:05:15,450
Do you agree?

128
00:05:15,450 --> 00:05:17,070
Let's try it.

129
00:05:17,070 --> 00:05:18,273
And that's correct.

130
00:05:19,440 --> 00:05:22,800
All right, this one is matching
the access control terms

131
00:05:22,800 --> 00:05:25,080
with their descriptions.

132
00:05:25,080 --> 00:05:28,680
We have standing privilege,
just-in-time PAM,

133
00:05:28,680 --> 00:05:30,810
or privilege access management,

134
00:05:30,810 --> 00:05:34,050
least privilege and
zero standing privilege.

135
00:05:34,050 --> 00:05:36,030
So, four terms that deal with privilege.

136
00:05:36,030 --> 00:05:38,580
Standing privilege, j i t, just-in-time,

137
00:05:38,580 --> 00:05:40,260
privilege access management

138
00:05:40,260 --> 00:05:43,560
least privilege, and
zero standing privilege.

139
00:05:43,560 --> 00:05:46,950
On the right hand side, we have
persistent privilege access,

140
00:05:46,950 --> 00:05:50,970
a methodology to grant
real-time privilege access,

141
00:05:50,970 --> 00:05:53,580
the requirement to
re-authenticate whenever

142
00:05:53,580 --> 00:05:55,080
privilege is invoked,

143
00:05:55,080 --> 00:05:57,990
and minimal rights and permissions.

144
00:05:57,990 --> 00:05:59,820
These are all really important concepts.

145
00:05:59,820 --> 00:06:02,490
Definitely put me on pause for
a moment and match these up.

146
00:06:02,490 --> 00:06:04,590
I wanna make sure you get these all right.

147
00:06:06,870 --> 00:06:08,850
Well, standing privilege, right there,

148
00:06:08,850 --> 00:06:10,620
it's persistent privilege access.

149
00:06:10,620 --> 00:06:13,263
It's having privilege, all the time.

150
00:06:14,640 --> 00:06:15,473
The next one,

151
00:06:15,473 --> 00:06:18,270
our methodology to grant
real-time privilege access,

152
00:06:18,270 --> 00:06:20,310
well, those match right there too.

153
00:06:20,310 --> 00:06:23,820
Right, that's our just in time
privilege access management.

154
00:06:23,820 --> 00:06:27,210
Now we have least privilege
and zero standing privilege.

155
00:06:27,210 --> 00:06:29,580
Either the requirement to
re-authenticate whenever

156
00:06:29,580 --> 00:06:31,020
privilege is invoked,

157
00:06:31,020 --> 00:06:33,630
or minimal rights and permissions.

158
00:06:33,630 --> 00:06:35,310
Well least privilege, right,

159
00:06:35,310 --> 00:06:37,650
is our principle that
we are going to assign

160
00:06:37,650 --> 00:06:40,110
minimal rights and permissions.

161
00:06:40,110 --> 00:06:41,610
And zero standing privilege,

162
00:06:41,610 --> 00:06:42,780
you know what that is,

163
00:06:42,780 --> 00:06:45,120
that's our requirement to re-authenticate

164
00:06:45,120 --> 00:06:48,180
whenever privilege is invoked, right?

165
00:06:48,180 --> 00:06:49,230
With zero standing,

166
00:06:49,230 --> 00:06:52,410
we're saying you always have
to be re-authenticating,

167
00:06:52,410 --> 00:06:55,170
or re-validated over
and over again, right?

168
00:06:55,170 --> 00:06:57,270
There is no inherent trust

169
00:06:57,270 --> 00:07:01,113
in a zero trust or zero
standing trust environment.

170
00:07:02,430 --> 00:07:03,263
You agree?

171
00:07:03,263 --> 00:07:04,800
Let's check it out.

172
00:07:04,800 --> 00:07:06,063
And that is correct.

173
00:07:07,920 --> 00:07:09,840
All right, this one is gonna be a hotspot.

174
00:07:09,840 --> 00:07:13,080
We're gonna have to choose
a point on the image.

175
00:07:13,080 --> 00:07:16,833
Which metric represents the
high point of user frustration?

176
00:07:17,700 --> 00:07:19,890
So we've got a couple of
different sections here.

177
00:07:19,890 --> 00:07:21,450
We've got our crossover error rate,

178
00:07:21,450 --> 00:07:24,720
that's the red dot with the yellow circle.

179
00:07:24,720 --> 00:07:28,020
The upper right hand side, we
have the false reject rate,

180
00:07:28,020 --> 00:07:30,870
or F R R, which are type one errors.

181
00:07:30,870 --> 00:07:34,650
And down below, we have
the fault accept rate,

182
00:07:34,650 --> 00:07:37,320
the F R R, the type two errors.

183
00:07:37,320 --> 00:07:38,820
So which one of these

184
00:07:38,820 --> 00:07:41,760
represents the high point
of user frustration?

185
00:07:41,760 --> 00:07:46,488
The C E R, the F R R, or the F A R?

186
00:07:46,488 --> 00:07:48,413
Go ahead and think
about that for a moment.

187
00:07:50,130 --> 00:07:52,440
Well, I'm gonna point to,

188
00:07:52,440 --> 00:07:53,670
see if I can get it so it's not on there,

189
00:07:53,670 --> 00:07:54,570
so you can see it.

190
00:07:54,570 --> 00:07:55,830
The false reject rate,

191
00:07:55,830 --> 00:07:57,840
or F R R type one error.

192
00:07:57,840 --> 00:07:58,980
In a false reject rate,

193
00:07:58,980 --> 00:08:00,505
that's when we have tuned our system

194
00:08:00,505 --> 00:08:02,910
for a high sensitivity,

195
00:08:02,910 --> 00:08:05,310
there's a chance of a
legitimate user would not

196
00:08:05,310 --> 00:08:07,200
be allowed to be authenticated.

197
00:08:07,200 --> 00:08:08,820
Because maybe there's just something

198
00:08:08,820 --> 00:08:11,040
a little bit different in their finger,

199
00:08:11,040 --> 00:08:13,364
in their eye, however we're

200
00:08:13,364 --> 00:08:16,110
biometrically authenticating them.

201
00:08:16,110 --> 00:08:16,943
They've got a cold,

202
00:08:16,943 --> 00:08:19,320
so their voice sounds
a little bit different.

203
00:08:19,320 --> 00:08:22,080
And so, the system is so sensitive,

204
00:08:22,080 --> 00:08:25,080
that we're going to
reject legitimate users.

205
00:08:25,080 --> 00:08:27,240
And that is a source of user frustration.

206
00:08:27,240 --> 00:08:31,080
So I'm gonna go with false
reject rate type one errors.

207
00:08:31,080 --> 00:08:32,400
Did you agree?

208
00:08:32,400 --> 00:08:33,390
All right.

209
00:08:33,390 --> 00:08:34,593
And that is correct.

210
00:08:36,450 --> 00:08:38,340
In an ABAC model,

211
00:08:38,340 --> 00:08:41,130
which of these attributes
are avail, validated?

212
00:08:41,130 --> 00:08:43,440
And you can choose all that apply.

213
00:08:43,440 --> 00:08:47,853
Object, rules, subject,
environmental conditions.

214
00:08:49,410 --> 00:08:51,000
So we talked about ABAC, right?

215
00:08:51,000 --> 00:08:52,680
Attribute based access control.

216
00:08:52,680 --> 00:08:56,070
We said lots of different
attributes are evaluated.

217
00:08:56,070 --> 00:08:57,930
So I want you to choose all that apply.

218
00:08:57,930 --> 00:09:00,083
You can put me on pause
while you think about it.

219
00:09:01,920 --> 00:09:03,363
Well, in an ABAC model,

220
00:09:04,530 --> 00:09:07,830
the attributes of the
object are evaluated,

221
00:09:07,830 --> 00:09:11,370
the attributes of the
subject are evaluated,

222
00:09:11,370 --> 00:09:14,760
rules are evaluated, and operational

223
00:09:14,760 --> 00:09:18,210
or environmental conditions
are also evaluated.

224
00:09:18,210 --> 00:09:19,950
So all of them.

225
00:09:19,950 --> 00:09:20,880
Do you agree?

226
00:09:20,880 --> 00:09:22,260
Let's check.

227
00:09:22,260 --> 00:09:23,463
And that is correct.

228
00:09:26,149 --> 00:09:28,080
Okay, in this access control model,

229
00:09:28,080 --> 00:09:29,747
access is based on the relationship

230
00:09:29,747 --> 00:09:33,660
between the subject's clearance
and their need to know,

231
00:09:33,660 --> 00:09:36,360
and the objects classification level.

232
00:09:36,360 --> 00:09:41,360
Is the DAC, MAC, ABAC or RBAC?

233
00:09:41,610 --> 00:09:43,320
DAC, discretionary access control,

234
00:09:43,320 --> 00:09:45,360
and MAC, mandatory access control,

235
00:09:45,360 --> 00:09:47,640
ABAC, attribute based access control,

236
00:09:47,640 --> 00:09:50,250
and RBAC, role-based access control.

237
00:09:50,250 --> 00:09:52,050
So that in this model, the access is based

238
00:09:52,050 --> 00:09:54,540
on the relationship between
the subject clearance

239
00:09:54,540 --> 00:09:56,100
and their need to know,

240
00:09:56,100 --> 00:09:58,380
and the objects classification.

241
00:09:58,380 --> 00:09:59,680
What are you gonna choose?

242
00:10:01,950 --> 00:10:03,450
Well, I'm gonna choose MAC,

243
00:10:03,450 --> 00:10:05,520
mandatory access control,

244
00:10:05,520 --> 00:10:07,290
because that's the model that's based

245
00:10:07,290 --> 00:10:08,340
on the subject clearance,

246
00:10:08,340 --> 00:10:10,260
Remember, clearance is a level of trust,

247
00:10:10,260 --> 00:10:12,390
plus need to know, a demonstrated reason

248
00:10:12,390 --> 00:10:16,380
for acquiring access and the
objects classification level.

249
00:10:16,380 --> 00:10:19,020
So, if I have a clearance of top secret,

250
00:10:19,020 --> 00:10:21,210
I should be able to get
to top secret information,

251
00:10:21,210 --> 00:10:22,770
but I can't get to everything.

252
00:10:22,770 --> 00:10:23,850
I also have to have a

253
00:10:23,850 --> 00:10:25,830
demonstrated need to know.

254
00:10:25,830 --> 00:10:26,820
What are the others?

255
00:10:26,820 --> 00:10:29,040
In DAC, discretionary access control,

256
00:10:29,040 --> 00:10:31,200
that's when the owner of the the data,

257
00:10:31,200 --> 00:10:34,140
or the system, says who has access.

258
00:10:34,140 --> 00:10:36,870
ABAC, that's attribute
based access control.

259
00:10:36,870 --> 00:10:38,520
And there we're looking at the subject

260
00:10:38,520 --> 00:10:40,380
and the object and we're looking at rules

261
00:10:40,380 --> 00:10:42,840
and operational or
environmental conditions.

262
00:10:42,840 --> 00:10:44,940
And RBAC, role-based,

263
00:10:44,940 --> 00:10:47,280
that's where we're going to
put our users into roles,

264
00:10:47,280 --> 00:10:51,570
and then we will assign
the access to the roles.

265
00:10:51,570 --> 00:10:53,850
So I'm gonna go with MAC, do you agree?

266
00:10:53,850 --> 00:10:55,470
Let's check.

267
00:10:55,470 --> 00:10:56,643
And that is correct.

268
00:10:57,780 --> 00:11:00,060
All right, I want you to click on the name

269
00:11:00,060 --> 00:11:02,943
of the FIM technology
that is depicted here.

270
00:11:04,200 --> 00:11:07,080
We have a resource owner,

271
00:11:07,080 --> 00:11:10,020
we have a requesting client application,

272
00:11:10,020 --> 00:11:13,203
and, we have a resource
or authorization server.

273
00:11:15,360 --> 00:11:18,660
Is this SAML, OAuth two o,

274
00:11:18,660 --> 00:11:22,020
Kerberos, or OpenID?

275
00:11:22,020 --> 00:11:23,580
So, we have a picture here,

276
00:11:23,580 --> 00:11:24,660
and we need to choose,

277
00:11:24,660 --> 00:11:27,510
is this SAML, OAuth two o,

278
00:11:27,510 --> 00:11:30,780
Kerberos, or OpenID?

279
00:11:30,780 --> 00:11:32,370
Now first of all, it's a FIM technology,

280
00:11:32,370 --> 00:11:34,530
so should be able to
eliminate one right away,

281
00:11:34,530 --> 00:11:35,370
like Kerberos,

282
00:11:35,370 --> 00:11:36,780
which is not a FIM technology.

283
00:11:36,780 --> 00:11:39,360
So I'm giving you part of that answer.

284
00:11:39,360 --> 00:11:42,870
So now look at this, and say,
we've got the resource owner,

285
00:11:42,870 --> 00:11:45,000
the requesting client application,

286
00:11:45,000 --> 00:11:48,330
and the resource, and also a
resource authorization server

287
00:11:48,330 --> 00:11:50,283
application programming interface.

288
00:11:51,150 --> 00:11:54,780
This was the example I gave
you about playing poker.

289
00:11:54,780 --> 00:11:56,250
What is it?

290
00:11:56,250 --> 00:11:57,930
I'm gonna choose,

291
00:11:57,930 --> 00:12:00,060
OAuth two O, do you agree?

292
00:12:00,060 --> 00:12:02,400
All right, let's check it out.

293
00:12:02,400 --> 00:12:03,573
And that is correct.

294
00:12:06,360 --> 00:12:08,580
All right, which of the
following is an example

295
00:12:08,580 --> 00:12:11,580
of multilayer authentication?

296
00:12:11,580 --> 00:12:12,750
Multi layer,

297
00:12:12,750 --> 00:12:13,840
that's the key word here.

298
00:12:13,840 --> 00:12:15,360
Okay, you really wanna make sure

299
00:12:15,360 --> 00:12:17,700
that you're reading your
questions for comprehension.

300
00:12:17,700 --> 00:12:19,260
If you read this quickly, you might say

301
00:12:19,260 --> 00:12:21,990
which is a following
example of, of multifactor?

302
00:12:21,990 --> 00:12:24,210
'Cause that's what you
were expecting, right?

303
00:12:24,210 --> 00:12:26,400
This is an example of multilayer.

304
00:12:26,400 --> 00:12:28,290
A geolocation and a pin,

305
00:12:28,290 --> 00:12:30,420
a password and a finger scan,

306
00:12:30,420 --> 00:12:33,300
smart card and voice recognition,

307
00:12:33,300 --> 00:12:36,690
or cognitive and out of wallet questions.

308
00:12:36,690 --> 00:12:39,210
An example of multi-layer authentication.

309
00:12:39,210 --> 00:12:41,580
Okay, put me on pause as
you read through those.

310
00:12:41,580 --> 00:12:44,763
I wanna know which one's
the example of multi-layer?

311
00:12:46,410 --> 00:12:49,770
Remember that multi-layer is when I have,

312
00:12:49,770 --> 00:12:53,220
multiple layers of the same factor.

313
00:12:53,220 --> 00:12:54,510
So, let's go through these.

314
00:12:54,510 --> 00:12:55,800
Geolocation and pin,

315
00:12:55,800 --> 00:12:57,330
well, that would be somewhere I am

316
00:12:57,330 --> 00:12:58,950
or location and something I know.

317
00:12:58,950 --> 00:13:01,350
So, that's two different factors.

318
00:13:01,350 --> 00:13:02,550
Password in a finger scan,

319
00:13:02,550 --> 00:13:06,090
that's something I know and
something I am, or biometric.

320
00:13:06,090 --> 00:13:07,890
That's two different factors.

321
00:13:07,890 --> 00:13:09,780
A smart card and voice recognition,

322
00:13:09,780 --> 00:13:13,650
that's something I have and
something I am, or biometric.

323
00:13:13,650 --> 00:13:15,090
So that's two different factors.

324
00:13:15,090 --> 00:13:17,940
So, the first three, geolocation and pin,

325
00:13:17,940 --> 00:13:19,080
password and finger scan,

326
00:13:19,080 --> 00:13:20,730
and smart card and voice recognition

327
00:13:20,730 --> 00:13:21,930
are all two different factors.

328
00:13:21,930 --> 00:13:24,483
Those are all two factors authentication.

329
00:13:25,500 --> 00:13:27,750
The cognitive and out of wallet questions,

330
00:13:27,750 --> 00:13:29,310
those are both the same factor.

331
00:13:29,310 --> 00:13:32,340
They're both something I
would know the answer to.

332
00:13:32,340 --> 00:13:34,290
So that's gonna be my choice.

333
00:13:34,290 --> 00:13:35,220
You agree?

334
00:13:35,220 --> 00:13:36,480
I hope so.

335
00:13:36,480 --> 00:13:37,313
Let's try it,

336
00:13:37,313 --> 00:13:38,523
and it's right.

337
00:13:39,480 --> 00:13:41,640
All right, let's do our last question.

338
00:13:41,640 --> 00:13:45,330
Which statement is not true
about identity proofing?

339
00:13:45,330 --> 00:13:47,520
And again, I really want you
to look for those key words.

340
00:13:47,520 --> 00:13:49,380
In this case, not true, right,

341
00:13:49,380 --> 00:13:51,600
just means which one is false.

342
00:13:51,600 --> 00:13:55,650
Identity proofing is only
required for federated identity,

343
00:13:55,650 --> 00:13:57,360
identity proofing is a component

344
00:13:57,360 --> 00:13:59,850
of fraud and identity prevention,

345
00:13:59,850 --> 00:14:03,240
identity proofing involves
confirming the authenticity

346
00:14:03,240 --> 00:14:05,940
and accuracy of personal information,

347
00:14:05,940 --> 00:14:09,840
and identity proofing may
be a compliance requirement.

348
00:14:09,840 --> 00:14:11,730
Now, three of those are true statements,

349
00:14:11,730 --> 00:14:13,470
and one's a fault statement.

350
00:14:13,470 --> 00:14:14,490
Put me on pause if you want

351
00:14:14,490 --> 00:14:16,353
while you read through those again.

352
00:14:19,230 --> 00:14:20,400
Well, I'm gonna start at the bottom.

353
00:14:20,400 --> 00:14:22,950
Identity proofing may be
a compliance requirement.

354
00:14:22,950 --> 00:14:24,300
Definitely true.

355
00:14:24,300 --> 00:14:26,940
identity proofing involves
confirming the authenticity

356
00:14:26,940 --> 00:14:29,220
and accuracy of personal information.

357
00:14:29,220 --> 00:14:30,660
Absolutely.

358
00:14:30,660 --> 00:14:32,340
Identity proofing is a component

359
00:14:32,340 --> 00:14:34,830
of fraud and identity theft prevention.

360
00:14:34,830 --> 00:14:35,820
Definitely.

361
00:14:35,820 --> 00:14:38,130
So, so far we've got
three true statements.

362
00:14:38,130 --> 00:14:39,690
So what do we know about this one?

363
00:14:39,690 --> 00:14:43,500
Identity proofing is only
required for federated identity.

364
00:14:43,500 --> 00:14:44,520
That is false.

365
00:14:44,520 --> 00:14:45,900
Because of the word only.

366
00:14:45,900 --> 00:14:47,850
Now, identity proofing may be required

367
00:14:47,850 --> 00:14:50,790
for your federated identity,
but it says it's only required

368
00:14:50,790 --> 00:14:52,980
for federated identities,
and that's not true.

369
00:14:52,980 --> 00:14:56,400
We'll use identity proofing
whenever we have to,

370
00:14:56,400 --> 00:14:59,460
be able to, prove our an
identity to be genuine.

371
00:14:59,460 --> 00:15:00,723
So identity proofing.

372
00:15:02,190 --> 00:15:04,710
I'm gonna choose that
one and let's submit it.

373
00:15:04,710 --> 00:15:06,363
And that is correct.

374
00:15:07,710 --> 00:15:09,660
Awesome, 10 questions, you did great.

375
00:15:09,660 --> 00:15:11,010
Congratulations.

376
00:15:11,010 --> 00:15:13,440
Up next, we're gonna go into lesson 20

377
00:15:13,440 --> 00:15:14,910
and explain the importance of

378
00:15:14,910 --> 00:15:19,110
automation and orchestration
to secure operations.

379
00:15:19,110 --> 00:15:20,060
I'll see you there.
