CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard

A project manager is overseeing the implementation of a new enterprise resource planning (ERP) system. The system requires various departments (e.g., finance, HR, inventory) to access specific modules but restricts them from accessing sensitive information or functions outside their roles. To enforce these access limitations and ensure data security, which access control mechanism should be implemented?

  1. ADiscretionary Access Control (DAC)
  2. BMandatory Access Control (MAC)
  3. CRole-Based Access Control (RBAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: C. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) is the most suitable mechanism for an ERP system as it assigns permissions based on a user's organizational role, effectively allowing departments to access specific modules while restricting access to sensitive information outside their defined responsibilities.

Why the other options are wrong

  • A. DAC allows object owners to set permissions, which is too granular and difficult to manage in a large enterprise ERP system.
  • B. MAC applies strict, system-wide rules based on sensitivity labels, often used in high-security environments, and is overly complex for typical ERP departmental access.
  • D. ABAC grants access based on attributes of the user, resource, and environment, offering very fine-grained control but can be more complex to implement and manage than RBAC for role-specific access.

Role-Based Access Control (RBAC)

An access control mechanism that grants or denies access to resources based on the roles individual users have within an organization. Permissions are associated with roles, and users are assigned to roles.

  • Simplifies access management in large organizations.
  • Permissions are assigned to roles, not individual users.
  • Ensures users have only the access necessary for their job functions.

Memory trick: RBAC: Roles grant rights, keeping access clear and tight.

More Basics of IT and Governance questions