A software development team is adopting a microservices architecture and needs to secure inter-service communication. Each microservice should only be able to access the specific resources it needs, and this access should be dynamically managed based on its identity and context rather than static IP addresses or pre-shared keys. Which IAM concept would BEST facilitate this fine-grained, dynamic authorization for microservices?
- AMandatory Access Control (MAC)
- BAttribute-Based Access Control (ABAC)
- CDiscretionary Access Control (DAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is the most suitable model for fine-grained, dynamic authorization in a microservices architecture. ABAC evaluates access requests based on a set of attributes associated with the user (or service in this case), resource, action, and environment. This allows for highly flexible and dynamic policies that can adapt to changing contexts and identities, which is crucial for microservices that need to interact based on their specific roles, data they process, or current operational state, rather than fixed roles or permissions.
Why the other options are wrong
- A. MAC is typically used in highly secure, multi-level security environments (e.g., government, military) and enforces strict, system-wide rules based on security labels, which is typically too rigid for general microservices authorization.
- C. DAC allows resource owners to control access, which is not scalable or centrally manageable for inter-service communication in a microservices architecture.
- D. RBAC is based on predefined roles and permissions, which can become unwieldy and less flexible in a dynamic microservices environment with numerous services and contexts.
Attribute-Based Access Control (ABAC)
ABAC is an authorization model that grants or denies access to resources based on attributes (characteristics) of the user (or entity), the resource, the action being performed, and the environment context.
- Provides fine-grained and dynamic authorization.
- Highly flexible and scalable for complex environments.
- Uses policies defined by combinations of attributes.
- Well-suited for cloud and microservices architectures.
Memory trick: ABAC Attributes Adapt Access for Microservices