CompTIA Security+ (SY0-701)Security OperationsMedium
A security architect is designing a new cloud application and needs to implement granular access controls based on user attributes such as department, role, and current project, rather than just predefined roles. The system should dynamically grant or deny access to specific resources based on a combination of these attributes. Which access control model would BEST fit these requirements?
- AAttribute-Based Access Control (ABAC)
- BMandatory Access Control (MAC)
- CDiscretionary Access Control (DAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) uses a set of attributes (user, resource, environment) to define access policies. This allows for highly granular and dynamic control, where access decisions are made in real-time based on a combination of these attributes, perfectly matching the requirement for dynamic access based on department, role, and project.
Why the other options are wrong
- B. MAC is based on security labels and clearances, typically used in high-security environments, and is less flexible for dynamic business attributes.
- C. DAC allows resource owners to define access, which is not scalable or granular enough for dynamic, attribute-based access.
- D. RBAC assigns permissions to roles, and users inherit those permissions, but it's less granular and dynamic than ABAC for combining multiple attributes.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies access to resources based on a combination of attributes associated with the user, resource, and environment.
- Highly granular and flexible.
- Uses attributes (e.g., department, time of day).
- Access decisions are dynamic and policy-driven.
Memory trick: Access is GRANTED if all the ATTRIBUTES MATCH, like a detailed checklist.