CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsMedium

A file-sharing platform allows each document's creator to individually decide which other users may view, edit, or share that specific document, granting or revoking permissions at their own discretion without requiring administrator approval. Which access control model does this describe?

  1. ADiscretionary access control
  2. BRole-based access control
  3. CMandatory access control
  4. DAttribute-based access control
Show answer & explanation

Correct answer: A. Discretionary access control

Discretionary access control (DAC) allows the owner of a resource to determine and control who else can access it, at their own discretion. This is different from centrally enforced models such as MAC, RBAC, or ABAC.

Why the other options are wrong

  • B. RBAC assigns access based on predefined organizational roles, not individual owner decisions.
  • C. MAC uses centrally set, non-negotiable security labels/classifications, not owner discretion.
  • D. ABAC evaluates multiple attributes via policy engine, not owner-controlled permissions.

Discretionary Access Control (DAC)

An access control model in which the owner of a resource determines who is granted access and what permissions they receive.

  • Owner controls permissions, not a central authority
  • Common in file systems (e.g., Windows NTFS permissions)
  • Contrasts with MAC, which enforces centrally defined policies

Memory trick: DAC=owner decides, MAC=military/central rules, RBAC=role badge, ABAC=attribute checklist

More Data Governance, Quality and Controls questions