Systems Security Certified Practitioner – SSCP – Question0350

What can best be described as an abstract machine which must mediate all access to subjects to objects?

A.
A security domain
B. The reference monitor
C. The security kernel
D. The security perimeter

Correct Answer: B

Explanation:

The reference monitor is an abstract machine which must mediate all access to subjects to objects, be protected from modification, be verifiable as correct, and is always invoked. The security kernel is the hardware, firmware and software elements of a trusted computing base that implement the reference monitor concept. The security perimeter includes the security kernel as well as other security-related system functions that are within the boundary of the trusted computing base. System elements that are outside of the security perimeter need not be trusted. A security domain is a domain of trust that shares a single security policy and single management. Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.