CompTIA Security+ (SY0-701)Security OperationsMedium
A hospital's IT system automatically grants all users assigned the title "Nurse" access to the patient scheduling application, while users assigned "Billing Clerk" automatically receive access to the invoicing system. Access is not evaluated based on any other contextual factor. Which access control model is being used?
- ARole-based access control (RBAC)
- BDiscretionary access control (DAC)
- CAttribute-based access control (ABAC)
- DMandatory access control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Role-based access control (RBAC)
RBAC assigns permissions based on a user's defined job role or title, so all users in that role share identical access rights. ABAC evaluates multiple dynamic attributes (device, time, location) at runtime, DAC lets resource owners assign permissions individually, and MAC uses centrally defined classification labels.
Why the other options are wrong
- B. DAC lets individual resource owners grant access at their discretion.
- C. ABAC would evaluate multiple attributes dynamically, not just job title alone.
- D. MAC enforces access via classification labels set by a central authority.
Role-Based Access Control (RBAC)
An access control model where permissions are assigned to roles (job functions), and users inherit access rights by being assigned to a role.
- Simplifies administration for large user bases
- Access changes automatically when role changes
- Contrasts with ABAC, which uses multiple dynamic attributes
Memory trick: RBAC hands out a uniform (role) — everyone wearing it gets the same keys.