CompTIA SecurityX (CAS-005)Security EngineeringMedium

A large enterprise is migrating its legacy monolithic applications to a microservices architecture. The security team needs to implement fine-grained authorization policies that are dynamically evaluated at runtime, based on a variety of user, resource, and environmental attributes. These policies must be flexible enough to adapt to changing business logic without requiring code changes in each microservice. Which authorization model is BEST suited for this dynamic and attribute-rich environment?

  1. ARole-Based Access Control (RBAC)
  2. BDiscretionary Access Control (DAC)
  3. CMandatory Access Control (MAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: D. Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is the most suitable model for this scenario. It allows for dynamic, context-aware authorization decisions based on a combination of attributes (user, resource, environment). This flexibility is crucial in microservices environments where policies need to adapt without constant code changes, as RBAC, DAC, and MAC are more static or less granular.

Why the other options are wrong

  • A. RBAC grants permissions based on roles, which can be too static and coarse-grained for complex, dynamic microservices authorization.
  • B. DAC allows resource owners to define access, which can lead to inconsistent policies and is not centrally managed or dynamically evaluated.
  • C. MAC enforces system-wide security labels, which is typically for highly sensitive, multi-level security systems and less flexible for general enterprise microservices.

Attribute-Based Access Control (ABAC)

An authorization model that grants or denies access to resources based on attributes of the user, resource, action, and environment, allowing for highly granular and dynamic policy enforcement.

  • Uses attributes for authorization decisions.
  • Highly granular and dynamic.
  • Flexible for complex, changing environments.

Memory trick: ABAC is about ALL the ATTRIBUTES, not just roles.

More Security Engineering questions