CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing an access control system for a highly sensitive research laboratory. The system must enforce access decisions based on the clearance level of the researcher, the classification level of the data, and the need-to-know principle, where access is only granted if the researcher's clearance dominates the data's classification and they have a specific, approved reason to access it. This model must be strictly enforced and cannot be overridden by data owners. Which access control model is being described?

  1. ARole-Based Access Control (RBAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CDiscretionary Access Control (DAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: D. Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is a security model where access rights are governed by a central authority (the system) rather than the data owner. It uses security labels (e.g., classification levels, clearance levels) to determine access, enforcing strict rules like 'no-write-down' and 'no-read-up'. This aligns with the 'strictly enforced' and 'cannot be overridden' requirements.

Why the other options are wrong

  • A. RBAC grants permissions based on user roles, but it doesn't inherently enforce strict classification/clearance dominance or prevent owners from overriding.
  • B. ABAC uses attributes for granular access, but MAC specifically describes the strict, non-overridable, label-based approach for highly sensitive environments.
  • C. DAC allows data owners to grant or deny access, which conflicts with the 'cannot be overridden' requirement.

Mandatory Access Control (MAC)

An access control model where the operating system or security kernel enforces access decisions based on security labels assigned to subjects (users) and objects (data). Access cannot be overridden by data owners.

  • Centralized authority enforces access.
  • Uses security labels (e.g., Top Secret, Secret).
  • Strictly enforces 'no-read-up' and 'no-write-down' rules.
  • Common in military, government, and highly sensitive environments.

Memory trick: MAC is Mandatory, like a military command, no one can override the rules.

More Security Architecture questions