CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing an identity and access management (IAM) solution for an enterprise that requires fine-grained authorization decisions based on dynamic attributes of the user, resource, and environment. For example, access to a document might depend on the user's department, the document's classification, and the time of day. Which access control model is BEST suited for this complex requirement?
- AMandatory Access Control (MAC)
- BDiscretionary Access Control (DAC)
- CRole-Based Access Control (RBAC)
- DAttribute-Based Access Control (ABAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is designed for fine-grained authorization using policies that evaluate attributes of the user (e.g., department), resource (e.g., classification), and environment (e.g., time of day, location). This flexibility directly addresses the complex, dynamic requirements described.
Why the other options are wrong
- A. MAC enforces a strict, system-wide policy based on security labels, which is typically static and less flexible for dynamic, attribute-driven decisions.
- B. DAC allows resource owners to define access permissions, which is decentralized and lacks the centralized, policy-driven fine-grained control needed for complex attributes.
- C. RBAC grants permissions based on assigned roles, which can become unwieldy with many dynamic conditions and doesn't inherently support environmental attributes.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies access to resources based on an evaluation of attributes (characteristics) associated with the subject (user), object (resource), action, and environment.
- Provides fine-grained authorization
- Highly dynamic and flexible
- Scales well for complex access policies
Memory trick: ABAC: Access Based on Attributes - 'A'll 'B'e 'A'llowed if 'C'onditions are met.