CompTIA Security+ (SY0-701)Security OperationsMedium
A security administrator is configuring access controls for a new application. The policy states that 'users in the 'Managers' group can access financial reports only if their department is 'Sales' AND the current time is between 9 AM and 5 PM on a weekday.' Which access control model is being implemented?
- ARole-Based Access Control (RBAC)
- BMandatory Access Control (MAC)
- CDiscretionary Access Control (DAC)
- DAttribute-Based Access Control (ABAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) uses policies that combine multiple attributes about the user (e.g., group, department), the resource (e.g., financial reports), and the environment (e.g., time of day, location) to make access decisions. This scenario clearly demonstrates the use of multiple attributes beyond just roles.
Why the other options are wrong
- A. RBAC grants access based solely on a user's assigned role, which is one attribute but not comprehensive enough for this policy.
- B. MAC is a highly structured model based on security labels and clearance levels, not flexible attributes like time or department.
- C. DAC allows the resource owner to define access permissions, which is not described here.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies access based on a set of attributes assigned to users, resources, and environmental conditions.
- Highly flexible and granular access control.
- Uses 'if-then' type policies combining multiple attributes.
- Allows for dynamic access decisions based on context.
Memory trick: ABAC is 'All About Attributes' for access.