Registered users can read the full content for free
Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.
Page
1
Copyrights @ 2022 EC-Council International Ltd. 1Certified Cybersecurity Technician CERTIFIED CYBERSECURITY TECHNICIAN CHAPTER 4 IDENTIFICATION, AUTHENTICATION, AND AUTHORIZATION
Page
2
Copyrights @ 2022 EC-Council International Ltd. 2Certified Cybersecurity Technician INDEX Chapter 4: Identification, Authentication, and Authorization Exercise 1: Implement Access Controls in Windows Machine Exercise 2: Manage Access Controls in Linux Machine Exercise 3: Implement Role-Based Access Control in Windows Admin Center (WAC) Exercise 4: Implement Centralized Authentication Mechanism 05 35 57 86
Page
3
Copyrights @ 2022 EC-Council International Ltd. 3Certified Cybersecurity Technician SCENARIO The most serious risk faced by organizations involves unauthorized access to sensitive data. To control data breach events, organizations require strong identification, authentication, and authorization mechanisms to effectively manage the access to critical assets and sensitive data. The labs in this module will provide real-time experience in using the various methods and techniques employed for the identification, authentication, and authorization of users who access critical assets and resources. OBJECTIVE The objective of this lab is to provide expert knowledge in identifying, authenticating, and authorizing users who access critical assets and resources. This lab includes the following tasks: • Implementation of access control policies in Windows and Linux machines • Implementation of role-based access control using tools such as Windows Admin Center (WAC) • Implementation of centralized authentication using Windows utilities OVERVIEW OF IDENTIFICATION, AUTHENTICATION AND AUTHORIZATION Identification deals with confirming the identity of a user, process, or device accessing the network. User identification is the most commonly used technique for authenticating the users in the network and applications. Authentication involves verifying the credentials provided by a user while attempting to connect to a network. Both wired and wireless networks perform authentication of users before allowing them to access the resources in the network. Authorization refers to the process of providing permission to access the resources or perform an action on the network. Admin can decide the user privileges and access permissions of users on a multiuser system.
Page
4
Copyrights @ 2022 EC-Council International Ltd. 4Certified Cybersecurity Technician LAB TASKS Cyber security professionals or a security professionals use numerous tools and techniques to implement access control policies. The recommended labs that will assist you in learning various identification, authentication and authorization techniques include: Note: Turn on PfSense Firewall virtual machine and keep it running throughout the lab exercises. Implement Access Controls in Windows Machine01 Implement Role-Based Access Control in windows Admin Center (WAC)03 Manage Access Controls in Linux Machine02 Implement Centralized Authentication Mechanism04
Page
5
Copyrights @ 2022 EC-Council International Ltd. 5Certified Cybersecurity Technician EXERCISE 1: IMPLEMENT ACCESS CONTROLS IN WINDOWS MACHINE Access control is a method of limiting the access of an organization’s resources for the users. LAB SCENARIO A security professional must have the required knowledge to manage objects in the Active Directory using different types of accounts and know the application of account policies using GPO in Windows machine. OBJECTIVE This lab demonstrates the implementation of access control policies in Windows machine. OVERVIEW OF ACCESS CONTROL An access control function uses identification, authentication, and authorization mechanisms to identify, authenticate, and authorize the user who requests access to a specific resource. The access permissions determine the approvals or permissions provided to a user for accessing a system and other resources. A crucial aspect of implementing an access control is to maintain the integrity, confidentiality, and availability of information.
Page
6
Copyrights @ 2022 EC-Council International Ltd. 6Certified Cybersecurity Technician Note: Ensure that PfSense Firewall virtual machine is running. 1. Turn on the AD Domain Controller virtual machine. 2. In the AD Domain Controller virtual machine, log in with the credentials CCT\Administrator and admin@123. Note: The networks screen appears, click Yes. Note: If a Shutdown Event Tracker window appears, click Cancel. 3. Before implementing access control policies, we will first examine the properties of the current Administrator account. 4. Click Start icon on the Desktop, right-click Windows PowerShell and navigate to More Run as administrator. Note: If User Account Control pop-up appears, click Yes to continue. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
7
Copyrights @ 2022 EC-Council International Ltd. 7Certified Cybersecurity Technician E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E 5. In the PowerShell, type whoami /user and press Enter to display the details regarding Security ID (SID) and other additional information of the current user. Note: User accounts are identified in the system by their unique numbers. In Windows, this number is the Security Identifier (SID). In Linux, it is the User Identifier (UID).
Page
8
Copyrights @ 2022 EC-Council International Ltd. 8Certified Cybersecurity Technician 6. Now, type get-aduser -identity administrator -properties * and press Enter to display user account information. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
9
Copyrights @ 2022 EC-Council International Ltd. 9Certified Cybersecurity Technician 7. Minimize the Administrator: Windows PowerShell window. 8. Click Start icon in the Desktop, click Server Manager. 9. The Server Manager window appears, click Tools option at the top right corner of the window and select Active Directory Users and Computers option. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
10
Copyrights @ 2022 EC-Council International Ltd. 10Certified Cybersecurity Technician 10. Right-click CCT.com domain and navigate to New → Organizational Unit. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
11
Copyrights @ 2022 EC-Council International Ltd. 11Certified Cybersecurity Technician 11. New Object - Organizational Unit pop-up appears, type NetworkAdmin in the Name field and click OK. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
12
Copyrights @ 2022 EC-Council International Ltd. 12Certified Cybersecurity Technician 12. Right-click NetworkAdmin Organizational Unit, navigate to New → User. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
13
Copyrights @ 2022 EC-Council International Ltd. 13Certified Cybersecurity Technician 13. The New Object - User window appears, enter the following details and click Next: • First name: IT • Last name: Head • User logon name: IT_Head E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
14
Copyrights @ 2022 EC-Council International Ltd. 14Certified Cybersecurity Technician 14. Enter test@123 in both Password and Confirm Password fields. Uncheck User must change password at next logon and check Password never expires option. Click Next. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
15
Copyrights @ 2022 EC-Council International Ltd. 15Certified Cybersecurity Technician 15. In the next window, click Finish. 16. Now, we must create a global security group within the NetworkAdmin Organizational Unit. 17. Right-click NetworkAdmin Organizational Unit and navigate to New → Group. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
16
Copyrights @ 2022 EC-Council International Ltd. 16Certified Cybersecurity Technician 18. The New Object - Group window appears, type TechSupport in the Group name, leave all the other options set to default and click OK. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
17
Copyrights @ 2022 EC-Council International Ltd. 17Certified Cybersecurity Technician 19. Now, add the IT Head account to the TechSupport group. For this, right-click on IT Head and select Add to a group…. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
18
Copyrights @ 2022 EC-Council International Ltd. 18Certified Cybersecurity Technician 20. The Select Groups window appears, in the Enter the object names to select field, type Tech and click Check Names button. Then, the TechSupport name appears, click OK. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
19
Copyrights @ 2022 EC-Council International Ltd. 19Certified Cybersecurity Technician 21. A pop-up appears, indicating the successful addition of a user to the group. Click OK. E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
Page
20
Copyrights @ 2022 EC-Council International Ltd. 20Certified Cybersecurity Technician 22. Now, right-click FinanceOU Organizational Unit and navigate to New → Computer. 23. The New Object - Computer window appears, type Computer01 in the Computer Name field and click OK E X E R C IS E 1 : IM P LE M E N T A C C E S S C O N TR O LS IN W IN D O W S M A C H IN E
The above is a preview of the first 20 pages. Register to read the complete e-book.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
AI guide
【One-Line Pitch】
A hands-on lab companion for EC-Council's Certified Cybersecurity Technician Module 04, walking you step-by-step through Windows and Linux access control, role-based access in Windows Admin Center, and centralized RADIUS authentication. Best for certification candidates and junior admins who learn by doing in a virtualized lab.
【Book Arc】
- **Opening (~0%–8%)**: Frames the core problem — unauthorized access to sensitive data — and defines the three pillars (identification, authentication, authorization) before any tooling begins.
- **Early (~8%–33%)**: Exercise 1 builds Windows access control: creating users, groups, and computer objects in Active Directory, then enforcing password policy through Group Policy and verifying it with `gpresult`.
- **Early–Middle (~33%–50%)**: Exercise 2 shifts to Linux, covering local account and group creation, ownership, and permission bits via `chmod`, `usermod`, and `su` to test real access boundaries.
- **Middle–Late (~50%–75%)**: Exercise 3 introduces Windows Admin Center, installing it, connecting a server, and applying role-based access control so a user like John gets read-only visibility instead of full control.
- **Late (~75%–83%)**: Exercise 4 moves to centralized authentication, configuring a Network Policy Server as a RADIUS client/server and defining network policies tied to Windows groups.
- **Ending (~83%+)**: The excerpts do not cover the closing steps of Exercise 4 or any summary/assessment material.
【Key Takeaways】
- **Identification, authentication, and authorization are distinct stages** (Opening): identification confirms who is requesting access, authentication verifies credentials, and authorization grants permissions — the book treats them as a pipeline, not synonyms.
- **Windows identities are numeric under the hood** (Early): accounts map to Security Identifiers (SIDs), just as Linux uses UIDs, which matters when troubleshooting permission mismatches.
- **Group Policy is the enforcement layer for password rules** (Early): editing the Default Domain Policy and exporting results with `gpresult` shows how policy becomes auditable configuration documentation.
- **Linux access control is ownership plus permission bits** (Middle): creating users and groups, then setting `u/g/o` permissions with `chmod`, demonstrates least privilege at the filesystem level.
- **RBAC in Windows Admin Center limits blast radius** (Late): assigning the "Windows Admin Center Readers" role lets a user view settings but blocks actions like adding storage — a practical least-privilege demonstration.
- **Centralized authentication uses RADIUS and network policies** (Late): configuring NPS clients, shared secrets, and group-based conditions shows how many systems can trust one authentication authority.
- **Every exercise is verification-driven** (throughout): commands like `whoami /user`, `id`, `ls -ld`, and `gpresult` are used to confirm that changes actually took effect.
【Reading Tips】
- Treat this as a lab manual, not prose: read each exercise's Objective and Lab Scenario first, then follow steps at the keyboard.
- Deep-read the command syntax notes (e.g., `usermod -aG`, `chmod u=rwx,g=rwx,o=rx`) — these are the transferable skills; skim the repetitive screenshot-navigation steps.
- Watch for the environment prerequisites (PfSense firewall running, specific VM credentials) since skipping them breaks later exercises.
- Pay attention to the verification steps; reproducing them is the fastest way to confirm understanding before an exam.
【Coverage Limits】
This guide is based on stratified excerpts covering the module introduction and most of Exercises 1–4; the final steps of Exercise 4 and any concluding or assessment content are not covered.
Passage locations
Excerpt 1
书名: Certified Cybersecurity Technician - Module 04 - Identification, Authentication and Authorization - Lab (EC-Council) (Z-Library) 作者: EC-Council CHAPTER 4...
View in text
Excerpt 2
dow and select Active Directory Users and Computers option. Copyrights @ 2022 EC-Council International Ltd. Certified Cybersecurity Technician 9 EXERCISE 1:...
View in text
Excerpt 3
MACHINE EXERCISE 2: MANAGE ACCESS CONTROLS IN LINUX MACHINE Access control assists in maintaining the integrity, confidentiality, and availability of the inf...
View in text
Excerpt 4
Enter to set the following permission for user testuser02. Note: Here, rwx: read, write and execute permissions are given to u(user) and g(group), rx: Read a...
View in text
Recommended for You
{{#thumbnailUrl}}
{{/thumbnailUrl}}
{{^thumbnailUrl}}
{{/thumbnailUrl}}
Loading recommended books...
Failed to load, please try again later
Tip the Site
Scan the WeChat Pay or Alipay code to tip. No login required.
WeChat Pay
Alipay