CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud security engineer needs to implement a solution that allows granular control over individual API calls and resource access within a cloud environment. The solution should define 'who' (identity) can perform 'what' (actions) on 'which' (resources) under 'what' (conditions). Which IAM concept best fits this requirement?
- ADiscretionary Access Control (DAC)
- BAttribute-Based Access Control (ABAC)
- CMandatory Access Control (MAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) provides the most granular control by evaluating attributes of the user, resource, and environment at the time of the access request. This allows for highly dynamic and context-aware authorization policies, directly addressing the 'who, what, which, conditions' requirement.
Why the other options are wrong
- A. DAC allows resource owners to define access permissions, which can be complex and inconsistent in large cloud environments, and isn't inherently attribute-driven.
- C. MAC is a highly restrictive model based on security labels (e.g., classification levels) and is typically used in highly secure government or military systems, not commonly for granular API control in commercial cloud.
- D. RBAC grants permissions based on a user's assigned role, which is less granular and dynamic than ABAC, as it doesn't typically incorporate resource or environmental attributes into the decision.
Attribute-Based Access Control (ABAC)
ABAC is an authorization system that grants access based on attributes of the user, resource, and environment, allowing for highly granular and dynamic access policies.
- Uses 'who, what, which, conditions' for access decisions.
- More flexible and scalable than RBAC for complex environments.
- Policies are defined using logical expressions of attributes.
Memory trick: ABAC uses ALL attributes for access, not just roles.