CompTIA Security+ (SY0-701)Security OperationsHard
A security architect is designing a new cloud application and needs to implement granular access controls where permissions are granted dynamically based on user attributes (e.g., department, role, location), resource attributes (e.g., data sensitivity, creation date), and environmental conditions (e.g., time of day, IP address). Which access control model should the architect choose?
- ADiscretionary Access Control (DAC)
- BAttribute-Based Access Control (ABAC)
- CRole-Based Access Control (RBAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is the most flexible model, allowing access decisions to be made dynamically at runtime based on a combination of attributes associated with the user, resource, and environment. This contrasts with RBAC's static roles or DAC/MAC's more rigid structures.
Why the other options are wrong
- A. DAC allows resource owners to grant or deny access, which can be highly granular but lacks the centralized, policy-driven dynamic aspect based on multiple attributes.
- C. RBAC assigns permissions to roles, and users inherit those permissions by being assigned roles, which is less dynamic and granular than required by the scenario.
- D. MAC is a highly restrictive model based on security labels (sensitivity levels and categories), typically used in high-security environments, and is less focused on dynamic attribute evaluation.
Attribute-Based Access Control (ABAC)
An access control model where access rights are granted based on a combination of attributes associated with the user, the resource being accessed, and the environmental conditions.
- Most flexible and granular access control model.
- Decisions made dynamically at runtime.
- Uses policies rather than static roles or lists.
Memory trick: For 'Any' access, check 'All' the 'Attributes' with 'ABAC'.