CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsMedium
A company wants to grant database access based on employees' job functions, such as 'Sales Analyst' or 'HR Manager', rather than assigning permissions individually to each user. New employees automatically receive the correct permissions when assigned to a function. Which access control model should the company implement?
- AMandatory access control (MAC)
- BDiscretionary access control (DAC)
- CRole-based access control (RBAC)
- DAttribute-based access control (ABAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Role-based access control (RBAC)
RBAC assigns permissions to defined roles (like job functions) rather than individuals, and users inherit access automatically when assigned to that role, matching the scenario exactly.
Why the other options are wrong
- A. MAC uses fixed security classifications set by a central authority, not job-function roles.
- B. DAC lets individual data owners grant access at their discretion, not based on standardized roles.
- D. ABAC grants access based on multiple attributes (location, time, device), which is more complex than described here.
Role-Based Access Control (RBAC)
An access control model that assigns permissions to roles corresponding to job functions, and users inherit permissions by being assigned to a role.
- Simplifies management by grouping permissions into roles
- New users gain access instantly upon role assignment
- Contrasts with ABAC, which uses multiple contextual attributes
Memory trick: DAC=discretion, MAC=military, RBAC=role, ABAC=attribute soup.