CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is tasked with securing a critical government application that processes highly sensitive classified information. The design requires a multi-layered security approach, where data can only be accessed by users with the appropriate security clearance and 'need-to-know' for specific projects. The system must restrict access based on classification levels (e.g., Top Secret, Secret, Confidential) and compartments (e.g., Project A, Project B). Which access control model is best suited for implementing these stringent requirements?

  1. ADiscretionary Access Control (DAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CRole-Based Access Control (RBAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: D. Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is the most suitable model for environments requiring strict multi-level security, such as government or military systems. MAC assigns a security label (clearance level and compartment) to every subject and object, and the operating system or security kernel strictly enforces access rules based on these labels, preventing unauthorized disclosure even by data owners. The Bell-LaPadula model, a form of MAC, specifically addresses confidentiality.

Why the other options are wrong

  • A. DAC allows data owners to define access permissions, which is too permissive and insecure for highly sensitive classified information where system-wide enforcement is critical.
  • B. ABAC is highly flexible and can use attributes like clearance and project, but MAC (specifically models like Bell-LaPadula) is historically and fundamentally designed for the absolute enforcement of multi-level security and 'need-to-know' in classified environments, making it more directly aligned with the 'mandatory' and 'restrict' nature of the requirement.
  • C. RBAC grants permissions based on job roles, which is less granular and flexible than what's needed for multi-level security with 'need-to-know' and specific compartments.

Mandatory Access Control (MAC)

An access control model where the operating system or security kernel enforces access rules based on security labels assigned to subjects and objects, preventing unauthorized disclosure or modification.

  • Strictly enforced by the system, users cannot override.
  • Commonly used in highly secure environments (military, government).
  • Often implemented with multi-level security (e.g., Bell-LaPadula for confidentiality).

Memory trick: Access control models are like different 'gatekeepers' with their own rules for who gets in.

More Security Architecture questions