CompTIA Security+ (SY0-701)Security OperationsHard
A cloud security architect configures an access policy that grants a user access to a financial application only if all of the following are true at the time of the request: the user's department attribute equals "Finance," the device is corporate-managed, the request occurs during business hours, and the user's location is within the United States. The policy engine evaluates these conditions dynamically at each access attempt. Which access control model is being implemented?
- AMandatory access control (MAC)
- BDiscretionary access control (DAC)
- CAttribute-based access control (ABAC)
- DRole-based access control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Attribute-based access control (ABAC)
ABAC grants access based on the dynamic evaluation of multiple attributes (user, device, environment, resource) at the time of the request, matching a policy that combines department, device compliance, time, and location. RBAC would grant access based solely on assigned role without evaluating multiple contextual attributes together.
Why the other options are wrong
- A. MAC uses fixed classification labels set centrally, not dynamic attribute combinations.
- B. DAC allows resource owners to set access individually, not policy-engine attribute evaluation.
- D. RBAC assigns access strictly based on role, not multiple runtime attributes.
Attribute-Based Access Control (ABAC)
An access control model that grants permissions based on the dynamic evaluation of multiple attributes—such as user, device, environment, and resource—at the time of the access request.
- Evaluated in real time by a policy engine
- Can combine user, device, time, and location attributes
- Offers more granular, context-aware control than RBAC
Memory trick: ABAC checks a checklist of clues (attributes) before opening the door every single time.