CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A hospital's IT department configures its cloud IAM system so that all users are automatically granted the specific system permissions associated with their job title (e.g., nurse, billing clerk, administrator) rather than having permissions assigned individually to each person. Which access control model is being implemented?

  1. AAttribute-based access control (ABAC)
  2. BRole-based access control (RBAC)
  3. CDiscretionary access control (DAC)
  4. DMandatory access control (MAC)
Show answer & explanation

Correct answer: B. Role-based access control (RBAC)

Role-based access control (RBAC) assigns permissions based on predefined roles tied to job functions, so all users with the same role automatically receive the same set of access rights, matching the hospital's approach.

Why the other options are wrong

  • A. ABAC grants access based on multiple attributes (location, device, time) rather than a single role.
  • C. DAC allows resource owners to grant access individually at their discretion, not by predefined roles.
  • D. MAC uses fixed system-enforced classification labels, typically used in military/government contexts.

Role-Based Access Control (RBAC)

An access control model that assigns permissions to users based on their organizational role, rather than granting access individually.

  • Simplifies administration by grouping permissions by job function
  • Supports the principle of least privilege
  • Common in healthcare, enterprise IAM systems

Memory trick: RBAC = 'Role Badges Assign Clearance'

More Governance, Risk, Compliance and Security questions