CompTIA Security+ (SY0-701)Security OperationsHard
A security administrator is configuring access controls for a new application. The policy states that 'users in the 'Managers' group can access any document marked 'Confidential' if their department matches the document's department attribute, and the current time is between 9 AM and 5 PM on a weekday.' Which access control model is being implemented?
- ARole-Based Access Control (RBAC)
- BAttribute-Based Access Control (ABAC)
- CMandatory Access Control (MAC)
- DDiscretionary Access Control (DAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) uses a set of attributes (subject, object, environment) to make access decisions. The policy described is highly granular and depends on multiple attributes like user group, document classification, department, and time of day, which is characteristic of ABAC.
Why the other options are wrong
- A. RBAC assigns permissions based on a user's role, but does not typically incorporate environmental attributes like time of day or object-specific attributes beyond a simple classification.
- C. MAC assigns sensitivity labels to subjects and objects, enforcing a strict hierarchy, but it doesn't typically involve dynamic environmental attributes like time or granular matching of department attributes in this way.
- D. DAC allows the owner of a resource to define permissions, which is not the case here as a centralized policy is being configured.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies access to resources based on a set of attributes associated with the user, the resource, and the environment.
- Highly granular and flexible access decisions.
- Uses attributes like user role, department, resource sensitivity, time of day.
- Supports dynamic and context-aware access policies.
Memory trick: RDMA: Roles, Discretion, Mandatory, Attributes – each gets more complex.