還是看不懂,

3 views
Skip to first unread message

joanne lo

unread,
Nov 29, 2011, 10:19:00 AM11/29/11
to CISA 201110
Q626
R5-160 公司正在考慮利用指紋生物特徵識別技術在訪問關鍵性資料的電腦上,這就要求:
A. 對於所有可信任的用戶執行測試程式
B. 完全消除了錯誤接受的風險.
C. 可以通過單獨的密碼訪問指紋識別設備
D. 確保在非授權情況下不能訪問關鍵資料


Area: 5
160. A firm is considering using biometric fingerprint identification
on all PCs that access critical data. This requires:
A. that a registration process be executed for all accredited PC
users.
B. the full elimination of the risk of a false acceptance.
C. that the usage of the fingerprint reader be accessed by a separate
password.
D. assurance that it will be impossible to gain unauthorized access to
critical data.

The correct answer is:
A. that a registration process be executed for all accredited PC
users.


Explanation:
The fingerprints of accredited users need to be read, identified and
recorded, i.e., registered, before a user may operate the system from
the screened PCs. Choice B is incorrect, as the false-acceptance risk
of a biometric device may be optimized, but will never be zero because
this would imply an unacceptably high risk of false rejection. Choice
C is incorrect, as the fingerprint device reads the token (the user's
fingerprint) and does not need to be protected in itself by a
password. Choice D is incorrect because the usage of biometric
protection on PCs does not guarantee that other potential security
weaknesses in the system may not be exploited to access protected
data.

moris

unread,
Nov 30, 2011, 12:01:22 AM11/30/11
to CISA 201110
309.公司正在考慮當所有PC要存取關鍵資料時,要使用指紋生物識別技術。這會需要:A.所有認可的PC用戶執行註冊程序B.完全消除錯誤接受的風險
C.使用指紋識別器時須以獨立密碼存取D.保證未經授權存取關鍵資料不可能發生

答案A應該沒問題呀..
要作指紋辨識, 要先註冊使用者的指紋, 建立指紋資料庫

Reply all
Reply to author
Forward
0 new messages