CompTIA Cloud+ (CV0-004)SecurityEasy

A cloud security engineer is designing an access control strategy for a new critical application that will be hosted in a public cloud. The application processes highly sensitive customer data and requires strict segregation of duties. The engineer needs to ensure that users only have the minimum necessary permissions to perform their job functions and that these permissions are granted based on their organizational role rather than individual identity. Which of the following access control models best addresses these requirements?

  1. AMandatory Access Control (MAC)
  2. BRole-Based Access Control (RBAC)
  3. CDiscretionary Access Control (DAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: B. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) is ideal for environments requiring strict segregation of duties and permissions based on job functions, as it assigns permissions to roles, and users are then assigned to those roles. This ensures users have only the minimum necessary permissions.

Why the other options are wrong

  • A. MAC enforces access based on security labels and clearance levels, typically used in highly secure government or military environments, which is overly complex for this scenario.
  • C. DAC allows resource owners to define access, which can lead to inconsistent permissions and doesn't enforce segregation of duties effectively.
  • D. ABAC grants access based on various attributes of the user, resource, and environment, which is more dynamic but can be complex to manage for basic role-based segregation.

Role-Based Access Control (RBAC)

A method of restricting network access based on a user's role within an organization. Permissions are associated with roles, and users are assigned to appropriate roles.

  • Simplifies access management by grouping permissions.
  • Enforces segregation of duties.
  • Users inherit permissions from their assigned roles.

Memory trick: Roles Rule Access for Right Users.

More Security questions