CompTIA Security+ (SY0-701)Security OperationsHard
A security administrator is configuring access controls for a new application. The policy states that users can only access specific data if they are located within the corporate network, during business hours (9 AM to 5 PM), and belong to the 'Finance' group. Which access control model does this scenario BEST represent?
- ADiscretionary Access Control (DAC)
- BRole-Based Access Control (RBAC)
- CAttribute-Based Access Control (ABAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) uses attributes of the subject (e.g., user group), object (e.g., data type), action (e.g., read), and environment (e.g., network location, time of day) to make access decisions. This scenario explicitly uses environmental attributes (network location, time) in addition to a subject attribute (group membership), which is the hallmark of ABAC.
Why the other options are wrong
- A. DAC allows the owner of a resource to determine who has access, which is not described here.
- B. RBAC grants access based on a user's role, which is one attribute, but doesn't typically incorporate environmental factors like time or network location as primary decision points.
- D. MAC enforces access based on security labels (sensitivity, clearance) and is typically used in highly secure environments, not described here.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies user access to resources based on a set of attributes associated with the user, resource, action, and environment.
- Highly dynamic and granular
- Uses attributes like time, location, device health
- More flexible than RBAC
Memory trick: Access models: Who, what, when, where, why.