Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A hospital needs to ensure that patient medical records are accessible only by authorized healthcare professionals, and that those professionals can only view or modify the data relevant to their specific role (e.g., a nurse can update vitals, but only a doctor can diagnose). Additionally, the system must prevent unauthorized disclosure to external parties. Which security concept is being primarily addressed by ensuring access is limited to specific roles and preventing unauthorized disclosure?
- AAuditing and Data Retention
- BAvailability and Integrity
- CThreat Protection and eDiscovery
- DConfidentiality and Role-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Confidentiality and Role-Based Access Control (RBAC)
Preventing unauthorized disclosure aligns with Confidentiality, while limiting access based on specific job functions is a core aspect of Role-Based Access Control (RBAC). Both are critical for this scenario.
Why the other options are wrong
- A. Auditing tracks actions, and data retention manages how long data is kept; neither directly focuses on limiting access by role or preventing disclosure.
- B. Availability (uptime) and Integrity (accuracy) are important but don't directly address limiting access by role or preventing disclosure.
- C. Threat Protection guards against attacks, and eDiscovery retrieves data for legal purposes; these don't directly address role-based access or preventing disclosure.
Confidentiality and RBAC
Confidentiality ensures data privacy by restricting access to authorized individuals, often implemented using mechanisms like Role-Based Access Control (RBAC) to define what specific roles can access.
- Confidentiality prevents unauthorized data disclosure.
- RBAC assigns permissions based on user roles, enforcing 'need-to-know'.
- Crucial for sensitive data environments like healthcare.
Memory trick: Confidentiality keeps patient data private, RBAC ensures only the right roles see it.